A system log management tool with automatically generated log templates.
Project description
Amulog is a tool to support system log management. The main function is to classify log messages with automatically generated log templates (formats and variable locations), and to store the data in a database. This system works on python3.
Source: https://github.com/amulog/amulog
Bug Reports: https://github.com/amulog/amulog/issues
Author: Satoru Kobayashi
License: BSD-3-Clause
Main features
Support multiple databases: sqlite and mysql
Smart log segmentation with log2seq
Multiple template generation algorithms such as: Drain, SHISO, LenMa, FT-tree, Dlog, etc.
Support Online (incremental) and Offline (hindsight) use
Suspend and resume the template generation process
Import and Export log templates if you need
Edit log templates manually if you need
Search API with datetime, hostname and log template IDs
Ready-to-run examples for loghub open datasets (see example/loghub_*)
Tutorial
Install
$ pip install amulog
Generate config
For the first step, save following config as test.conf on an empty directory.
[general] src_path = logfile.txt src_recur = false logging = auto.log [database] database = sqlite3 sqlite3_filename = log.db [log_template] lt_methods = drain indata_filename = ltgen.dump
Then modify general.src_path option to a logfile you want to load.
(If you want to use multiple files, change general.src_recur into true and specify directory name to general.src_path.)
Generate database
Try following command to generate database:
$ python -m amulog db-make -c test.conf
Check database
$ python -m amulog show-db-info -c test.conf
shows status of the generated database.
$ python -m amulog show-lt -c test.conf
shows all generated log templates in the given logfile.
$ python -m amulog show-log -c test.conf ltid=2
shows all log messages corresponding to log template ID 2.
Resume generating database
Try following command to resume generating database:
$ python -m amulog db-add -c test.conf logfile2.txt
Export and Import templates
Following command exports all log templates in the database:
$ python3 -m amulog show-lt-import -c test.conf > exported_tpl.txt
You can modify the exported templates manually.
Note that some special letters (\\, @, *) are escaped in the exported templates.
To import the templates, save following config as test2.conf.
[general] src_path = logfile.txt src_recur = false logging = new_auto.log [database] database = sqlite3 sqlite3_filename = new_log.db [log_template] lt_methods = import indata_filename = new_ltgen.dump [log_template_import] def_path = exported_tpl.txt
Then, try generating database again:
python -m amulog db-make -c test2.conf
Using your data
Parsing your data
Amulog uses log2seq to parse input log messages in DB generation.
If your data is not a default syslog output format, you need to specify an appropriate log2seq parser script.
The log2seq parser script is specified in manager.parser_script in amulog config file.
[manager] parser_script = test_parser.py fail_output = fail.log
If the parser fails to parse some of the input log messages,
they are stored in manager.fail_output file.
You can check this file to test whether the parser is working appropriately or not.
There are example parser scripts in log2seq repository.
Further usage
see help with following command:
python -m amulog -h
Reference
This tool is demonstrated at International Journal of Network Management and CNSM2020.
If you use this code, please consider citing:
@article{Kobayashi_IJNM2022,
author = {Kobayashi, Satoru and Yamashiro, Yuya and Otomo, Kazuki and Fukuda, Kensuke},
title = {amulog: A general log analysis framework for comparison and combination of diverse template generation methods*},
journal = {International Journal of Network Management},
volume = {32},
number = {4},
pages = {e2195},
doi = {https://doi.org/10.1002/nem.2195},
year = {2022}
}
@inproceedings{Kobayashi_CNSM2020,
author = {Kobayashi, Satoru and Yamashiro, Yuya and Otomo, Kazuki and Fukuda, Kensuke},
booktitle = {Proceedings of the 16th International Conference on Network and Service Management (CNSM'20)},
title = {amulog: A General Log Analysis Framework for Diverse Template Generation Methods},
pages={1-5},
year = {2020}
}
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file amulog-0.4.0.tar.gz.
File metadata
- Download URL: amulog-0.4.0.tar.gz
- Upload date:
- Size: 121.6 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
80be9cdc049974b03df49b42e0b8542f0703e6941b0e95315f33a670aa77e1d0
|
|
| MD5 |
9d255299aee77026573bab95a2913040
|
|
| BLAKE2b-256 |
12169601627d120d2237df9dc1062a8a90d8c332e19862362949bbb637e9e476
|
Provenance
The following attestation bundles were made for amulog-0.4.0.tar.gz:
Publisher:
publish.yml on amulog/amulog
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
amulog-0.4.0.tar.gz -
Subject digest:
80be9cdc049974b03df49b42e0b8542f0703e6941b0e95315f33a670aa77e1d0 - Sigstore transparency entry: 1961421098
- Sigstore integration time:
-
Permalink:
amulog/amulog@167d8fa4e601bf4d2659d9e280f87360f977f3ff -
Branch / Tag:
refs/tags/v0.4.0 - Owner: https://github.com/amulog
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@167d8fa4e601bf4d2659d9e280f87360f977f3ff -
Trigger Event:
push
-
Statement type:
File details
Details for the file amulog-0.4.0-py3-none-any.whl.
File metadata
- Download URL: amulog-0.4.0-py3-none-any.whl
- Upload date:
- Size: 148.8 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2714012fdc99df8905bb674dcd2b2175b8e2b9962032db2de893232462dd484e
|
|
| MD5 |
1e69785d196c3a4fff662bad24cad9ba
|
|
| BLAKE2b-256 |
582505a187b67c4302b032c5f8e7a04620a87eb8af2db96be2fa213a85910d41
|
Provenance
The following attestation bundles were made for amulog-0.4.0-py3-none-any.whl:
Publisher:
publish.yml on amulog/amulog
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
amulog-0.4.0-py3-none-any.whl -
Subject digest:
2714012fdc99df8905bb674dcd2b2175b8e2b9962032db2de893232462dd484e - Sigstore transparency entry: 1961421273
- Sigstore integration time:
-
Permalink:
amulog/amulog@167d8fa4e601bf4d2659d9e280f87360f977f3ff -
Branch / Tag:
refs/tags/v0.4.0 - Owner: https://github.com/amulog
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
publish.yml@167d8fa4e601bf4d2659d9e280f87360f977f3ff -
Trigger Event:
push
-
Statement type: