A Critical Review of Common Log Data Sets Used for Evaluation of Sequence-Based Anomaly Detection Techniques
Max Landauer, Florian Skopik, Markus Wurzenberger
Abstract
Log data store event execution patterns that correspond to underlying workflows of systems or applications. While most logs are informative, log data also include artifacts that indicate failures or incidents. Accordingly, log data are often used to evaluate anomaly detection techniques that aim to automatically disclose unexpected or otherwise relevant system behavior patterns. Recently, detection approaches leveraging deep learning have increasingly focused on anomalies that manifest as changes of sequential patterns within otherwise normal event traces. Several publicly available data sets, such as HDFS, BGL, Thunderbird, OpenStack, and Hadoop, have since become standards for evaluating these anomaly detection techniques, however, the appropriateness of these data sets has not been closely investigated in the past. In this paper we therefore analyze six publicly available log data sets with focus on the manifestations of anomalies and simple techniques for their detection. Our findings suggest that most anomalies are not directly related to sequential manifestations and that advanced detection techniques are not required to achieve high detection rates on these data sets.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d806f854-3cdb-4924-a3ab-c461815767aeCited by top-tier papers4
- Multivariate Log-based Anomaly Detection for Distributed DatabaseLingzhe Zhang, Tong Jia, Mengxi Jia, Ying Li et al.KDD 2024 · 13 citations
- End-to-End AutoML for Unsupervised Log Anomaly DetectionShenglin Zhang, Yuhe Ji, Jiaqi Luan, Xiaohui Nie et al.ASE 2024 · 6 citations
- CoLA: Model Collaboration for Log-based Anomaly DetectionXuhang Zhu, Xiu Tang, Sai Wu, Jichen Li et al.VLDB 2025 · 2 citations
- EventADL: Open-Box Anomaly Detection and Localization Framework for Events in Cloud-Based Service SystemsLuan Pham, Victor Nicolet, Joey Dodds, Hui Guan et al.FSE 2026
Builds on3
- DeepLog: Anomaly Detection and Diagnosis from System Logs through Deep LearningMin Du, Feifei Li, Guineng Zheng, Vivek SrikumarCCS 2017 · 1,823 citations
- Semi-supervised Log-based Anomaly Detection via Probabilistic Label EstimationLin Yang, Junjie Chen, Zan Wang, Weijing Wang et al.ICSE 2021 · 216 citations
- Log-based Anomaly Detection with Deep Learning: How Far Are We?Van-Hoang Le, Hongyu ZhangICSE 2022 · 212 citations
Related papers
- Deep Learning or Classical Machine Learning? An Empirical Study on Log-Based Anomaly DetectionBoxi Yu, Jiayi Yao, Qiuai Fu, Zhiqing Zhong et al.ICSE 2024 · 49 citations
- MetaLog: Generalizable Cross-System Anomaly Detection from Logs with Meta-LearningChenyangguang Zhang, Tong Jia, Guopeng Shen, Pinyan Zhu et al.ICSE 2024 · 28 citations
- DeepTraLog: Trace-Log Combined Microservice Anomaly Detection through Graph-based Deep LearningChenxi Zhang, Xin Peng, Chaofeng Sha, Ke Zhang et al.ICSE 2022 · 163 citations
- Pluto: Sample Selection for Robust Anomaly Detection on Polluted Log DataLei Ma, Lei Cao, Peter M. VanNostrand, Dennis M. Hofmann et al.SIGMOD 2025 · 3 citations
- AutoLog: A Log Sequence Synthesis Framework for Anomaly DetectionYintong Huo, Yichen Li, Yuxin Su, Pinjia He et al.ASE 2023 · 12 citations
