Protocol-Sensitive Evaluation of Log Anomaly Detection: Component Costs and Target-Access Sensitivity on HDFS and BGL
Organizations: Fortinet, Inc. Sunnyvale, USA · Google LLC Mountain View, USA · Independent Researcher Mountain View, USA · Sony Corporate of America San Jose, USA
Abstract
Protocol choices can change the conclusions drawn from log anomaly detection benchmarks even when detector settings are fixed. We present a joint empirical study of split construction, representation visibility, and component costs using six fixed count, sequence, and semantic configurations on Hadoop Distributed File System (HDFS) and Blue Gene/L (BGL) logs. Random splits place several configurations near the average-precision ceiling, whereas group-disjoint HDFS and chronological BGL evaluation produce lower scores and different observed orderings. At a fixed BGL cutoff, parser choice spans 0.124 in semantic XGBoost mean average precision while preserving its lead over count XGBoost; the earliest rolling period reverses that ordering. A two-factor cross-system ablation contrasts source-only representations with offline transductive access to unlabeled target templates through the representation corpus and inverse document frequency: HDFS-to-BGL mean average precision moves from 0.191 with source-only access to 0.325 with union-corpus, target-IDF access, and the intermediate conditions reveal direction-dependent interactions in average precision and retrieval at fixed review budgets. Component-level profiling separates parsing and representation costs from classifier training, prediction, and storage. Together, these findings connect detector comparisons to the test population, preprocessing state, visible information, and measured pipeline stages, and identify the protocol fields needed alongside a score to support interpretable comparisons of log anomaly detection accuracy and resource use.
Figures & tables
| Characteristic | HDFS | BGL |
|---|---|---|
| Unit | block session | 100-line window |
| Sessions/windows | 575,061 | 47,479 |
| Anomalies | 16,838 (2.93%) | 4,802 (10.11%) |
| Event vocabulary | 29 | 2,746 |
| Mean length | 19.4 | 100 |
| Distinct count vectors | 589 | 6,280 |
| Model | Configuration |
|---|---|
| LR | inverse regularization; balanced weights; 1,000 iterations; standardized input |
| RF | 200 trees; balanced-subsample class weights |
| XGBoost | 300 trees; depth 6; rate 0.1; histogram method; class-ratio positive weight |
| Word2vec | skip-gram; 100 dimensions; window 5; minimum count 1; 30 epochs |
| LSTM | 32-d embedding; 64 hidden; Adam ; batch 256; at most five epochs |
| Random split | Group-disjoint | |||
|---|---|---|---|---|
| Configuration | AP | AP | ||
| Count/LR | .991 .004 | .989 .006 | .867 .103 | .934 .046 |
| Count/RF | 1.000 .000 | .998 .000 | .743 .227 | .808 .259 |
| Count/XGB | .999 .001 | .998 .000 | .692 .175 | .582 .337 |
| Sequence/LSTM | .999 .001 | .993 .002 | .627 .210 | .502 .324 |
| Semantic/LR | .982 .003 | .981 .003 | .725 .174 | .792 .275 |
| Random split | Chronological | |||
|---|---|---|---|---|
| Configuration | AP | AP | ||
| Count/LR | .987 .003 | .976 .004 | .277 .000 | .423 .000 |
| Count/RF | .998 .001 | .984 .002 | .388 .005 | .400 .012 |
| Count/XGB | .998 .001 | .989 .004 | .448 .000 | .396 .000 |
| Sequence/LSTM | .946 .012 | .916 .017 | .236 .151 | .282 .091 |
| Semantic/LR | .916 .006 | .870 .007 | .205 .095 | .267 .043 |
| Test anomaly | Count/XGB | LSTM | Semantic/XGB | ||
|---|---|---|---|---|---|
| Panel | Setting | rate | AP | AP | AP |
| Parser | Compact | 10.1% | .460 .000 | – | .741 .054 |
| Parser | Compact | 10.1% | .448 .000 | – | .676 .086 |
| Parser | Compact | 10.1% | .448 .000 | – | .631 .109 |
| Parser | Drain3 | 10.1% | .432 .000 | – | .617 .177 |
| Rolling | 50 60% | 1.3% | .902 .000 | .475 .147 | .838 .047 |
| System | Configuration | Fit (s) | Infer. (k/s) | Size (MB) |
|---|---|---|---|---|
| HDFS | Count/LR | 2.6 1.1 | 6771 2151 | .002 |
| HDFS | Count/RF | 17.8 2.1 | 312 91 | 2.234 |
| HDFS | Count/XGB | 3.8 1.8 | 660 94 | .423 |
| HDFS | Sequence/LSTM | 309.3 13.2 | 37 4 | .116 |
| HDFS | Semantic/LR | 31.4 21.3 | 1257 113 | .004 |
| HDFS | Semantic/XGB | 9.4 .8 | 696 189 | .416 |
| Word2vec | IDF | AP | P@1% | R@1% | P@5% | R@5% |
|---|---|---|---|---|---|---|
| HDFS BGL | ||||||
| Source | Source | .191 .107 | .242 .160 | .024 .016 | .220 .174 | .109 .086 |
| Source | Target | .187 .084 | .259 .163 | .026 .016 | .253 .163 | .125 .081 |
| Union | Source | .297 .136 | .443 .266 | .044 .026 | .293 .021 | .145 .010 |
| Union | Target | .325 .159 | .446 .312 | .044 .031 | .318 .122 | .157 .060 |
| BGL HDFS | ||||||