Skip to main navigation Skip to search Skip to main content

A graph-based file-level anomaly detection framework for system logs

  • Yanni Tang
  • , Wenjing Xiong
  • , Zhuoxing Zhang
  • , Kaiqi Zhao
  • , Jiamou Liu
  • , Kui Liu
  • , Wu Chen*
  • *Corresponding author for this work
  • Southwest University
  • The University of Auckland
  • Harbin Institute of Technology Shenzhen
  • Huawei Hong Kong Research Center

Research output: Contribution to journalArticlepeer-review

Abstract

System logs are crucial for monitoring system status and detecting anomalies. In the literature, logs have been pre-processed to extract event sequences that are further fed into the dedicated neural network-based models to detect anomalies, achieving promising performance. Unfortunately, such methods ignore the context information and complex event relationships. Although a few graph-based methods address this, they utilize temporal structure between log events and mainly focus on log segment classification. In this paper, we propose a novel framework termed Deep Graph-based Log Anomaly Detection (DeepGraLog), which advances detection granularity to the code file level. First, DeepGraLog uses a novel graph representation learning module to capture event relationships and code file interactions. This graph representation enables both anomaly detection and source code localization. Second, it introduces the weighted static call graph, for the first time, to delineate an overview of system functionality from the perspective of business logic, further improving the performance of log anomaly detection. Third, due to dataset limitations, we created two new datasets to serve our task, additionally adding the dynamic call information and root cause labeled in code files. Experiments show that DeepGraLog consistently outperforms existing methods. Across all evaluation settings, it achieves an average F1-score gain of 9.995% over the second-best baseline, demonstrating robust performance.

Original languageEnglish
Article number115345
JournalEngineering Applications of Artificial Intelligence
Volume181
DOIs
StatePublished - 1 Oct 2026
Externally publishedYes

Keywords

  • Graph representation learning
  • Log analysis
  • Log anomaly detection

Fingerprint

Dive into the research topics of 'A graph-based file-level anomaly detection framework for system logs'. Together they form a unique fingerprint.

Cite this