综述大模型在日志解析中的应用,梳理29种方法并公开评测结果。
System Log Parsing with Large Language Models: A Review
- 系统梳理29种基于大模型的日志解析方法
- 在公开数据集上评测7种方法,验证结果可复现性
- 提供代码与评测数据,推动领域标准化
日志数据对监控、根因分析和异常检测等任务至关重要。由于日志量庞大,自动化日志解析成为将半结构化日志转换为结构化表示的关键。大语言模型(LLM)的进展催生了基于大模型的日志解析新方向。尽管结果令人鼓舞,但该新兴领域尚无系统性综述,最早研究发表于2023年末。本文系统回顾了29种基于大模型的日志解析方法,在公开数据集上对其中7种进行基准测试,并批判性评估其可比性和结果复现性。研究总结了该领域的进展,提出关于结果报告、数据集选择、评估指标与术语使用的建议,并指出需避免的不一致之处,所有代码与结果均公开以确保透明。
原文摘要 · Abstract (English)
Log data provides crucial insights for tasks like monitoring, root cause analysis, and anomaly detection. Due to the vast volume of logs, automated log parsing is essential to transform semi-structured log messages into structured representations. Recent advances in large language models (LLMs) have introduced the new research field of LLM-based log parsing. Despite promising results, there is no structured overview of the approaches in this relatively new research field with the earliest advances published in late 2023. This work systematically reviews 29 LLM-based log parsing methods. We benchmark seven of them on public datasets and critically assess their comparability and the reproducibility of their reported results. Our findings summarize the advances of this new research field, with insights on how to report results, which data sets, metrics and which terminology to use, and which inconsistencies to avoid, with code and results made publicly available for transparency.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。