Interpretable Online Log Analysis Using Large Language Models with Prompt Strategies

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Liu, Yilun, Tao, Shimin, Meng, Weibin, Wang, Jingyu, Ma, Wenbing, Zhao, Yanqing, Chen, Yuhang, Yang, Hao, Jiang, Yanfei, Chen, Xun
Format: Preprint
Veröffentlicht: 2023
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866916105644146688
author Liu, Yilun
Tao, Shimin
Meng, Weibin
Wang, Jingyu
Ma, Wenbing
Zhao, Yanqing
Chen, Yuhang
Yang, Hao
Jiang, Yanfei
Chen, Xun
author_facet Liu, Yilun
Tao, Shimin
Meng, Weibin
Wang, Jingyu
Ma, Wenbing
Zhao, Yanqing
Chen, Yuhang
Yang, Hao
Jiang, Yanfei
Chen, Xun
contents Automated log analysis is crucial in modern software-intensive systems for facilitating program comprehension throughout software maintenance and engineering life cycles. Existing methods perform tasks such as log parsing and log anomaly detection by providing a single prediction value without interpretation. However, given the increasing volume of system events, the limited interpretability of analysis results hinders analysts' comprehension of program status and their ability to take appropriate actions. Moreover, these methods require substantial in-domain training data, and their performance declines sharply (by up to 62.5%) in online scenarios involving unseen logs from new domains, a common occurrence due to rapid software updates. In this paper, we propose LogPrompt, a novel interpretable log analysis approach for online scenarios. LogPrompt employs large language models (LLMs) to perform online log analysis tasks via a suite of advanced prompt strategies tailored for log tasks, which enhances LLMs' performance by up to 380.7% compared with simple prompts. Experiments on nine publicly available evaluation datasets across two tasks demonstrate that LogPrompt, despite requiring no in-domain training, outperforms existing approaches trained on thousands of logs by up to 55.9%. We also conduct a human evaluation of LogPrompt's interpretability, with six practitioners possessing over 10 years of experience, who highly rated the generated content in terms of usefulness and readability (averagely 4.42/5). LogPrompt also exhibits remarkable compatibility with open-source and smaller-scale LLMs, making it flexible for practical deployment. Code of LogPrompt is available at https://github.com/lunyiliu/LogPrompt.
format Preprint
id arxiv_https___arxiv_org_abs_2308_07610
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Interpretable Online Log Analysis Using Large Language Models with Prompt Strategies
Liu, Yilun
Tao, Shimin
Meng, Weibin
Wang, Jingyu
Ma, Wenbing
Zhao, Yanqing
Chen, Yuhang
Yang, Hao
Jiang, Yanfei
Chen, Xun
Software Engineering
Computation and Language
Automated log analysis is crucial in modern software-intensive systems for facilitating program comprehension throughout software maintenance and engineering life cycles. Existing methods perform tasks such as log parsing and log anomaly detection by providing a single prediction value without interpretation. However, given the increasing volume of system events, the limited interpretability of analysis results hinders analysts' comprehension of program status and their ability to take appropriate actions. Moreover, these methods require substantial in-domain training data, and their performance declines sharply (by up to 62.5%) in online scenarios involving unseen logs from new domains, a common occurrence due to rapid software updates. In this paper, we propose LogPrompt, a novel interpretable log analysis approach for online scenarios. LogPrompt employs large language models (LLMs) to perform online log analysis tasks via a suite of advanced prompt strategies tailored for log tasks, which enhances LLMs' performance by up to 380.7% compared with simple prompts. Experiments on nine publicly available evaluation datasets across two tasks demonstrate that LogPrompt, despite requiring no in-domain training, outperforms existing approaches trained on thousands of logs by up to 55.9%. We also conduct a human evaluation of LogPrompt's interpretability, with six practitioners possessing over 10 years of experience, who highly rated the generated content in terms of usefulness and readability (averagely 4.42/5). LogPrompt also exhibits remarkable compatibility with open-source and smaller-scale LLMs, making it flexible for practical deployment. Code of LogPrompt is available at https://github.com/lunyiliu/LogPrompt.
title Interpretable Online Log Analysis Using Large Language Models with Prompt Strategies
topic Software Engineering
Computation and Language
url https://arxiv.org/abs/2308.07610