Visual and algorithmic tooling for system trace analysis: a case study

Visual and algorithmic tooling for system trace analysis: a case study
复制标题

用于系统跟踪分析的视觉和算法工具:案例研究

DOI:
--
复制
发表时间:
2010
期刊:
OPSR
影响因子:
--
通讯作者:
S. Heisig
S. Heisig
中科院分区:
--
文献类型:
--
作者:
Wim De Pauw;S. Heisig

文献摘要

被引文献

相似文献

尽管自动化统计和机器学习技术在系统日志和跟踪数据的应用方面取得了进展,但始终需要对机器跟踪进行人工分析,因为不稳定系统上的跟踪信息可能不完整或不正确。此外,自动化分析的误报不太可能消失,需要评估补救措施和候选修复测试。我们提出Zinsight,一个可视化和分析工具,支持性能分析和调试,使用大型事件跟踪来了解复杂的系统。此工具使分析人员能够快速创建和操作与从底层事件跟踪数据中导出的统计分析相关联的高级结构表示。原始的原始跟踪用模块名称进行注释,并且将特定于域的数据库并入以将软件功能与模块名称相关联。可导航序列上下文图视图从任意可定义的事件集合中自动提取执行流模式,并链接到频率,分布和响应时间视图。目标是减少分析师的认知和计算负荷,同时在问题确定会话中为最自然的问题提供答案。我们提出了一个案例研究的工具,在现场使用的问题,从最近出货(2008年底)IBM z10大型机。由于行业趋向于更高的并行性和内存延迟,遗留代码遇到了许多问题。该工具已成功应用于诊断这些问题。
Despite advances in the application of automated statistical and machine learning techniques to system log and trace data there will always be a need for human analysis of machine traces, because trace information on unstable systems may be incomplete, or incorrect. In addition, false positives from automated analysis will not likely disappear, and remediation measures and candidate fix tests will need to be evaluated. We present Zinsight, a visual and analytic tool that supports performance analysts and debugging, using large event traces to understand complex systems. This tool enables analysts to quickly create and manipulate high-level structural representations linked with statistical analysis derived from the underlying event trace data. The original raw trace is annotated with module names and a domain specific database is incorporated to relate software functions to module names. Navigable sequence context graph views present automatically extracted execution flow patterns from arbitrarily definable sets of events and are linked to frequency, distribution, and response time views. The goal is to reduce the cognitive and computational load on the analyst while providing answers to the most natural questions in a problem determination session. We present a case study of the tool in use on field problems from the recently shipped (late 2008) IBM z10 mainframe. As a result of the industry trend toward higher parallelism and memory latency, many issues were encountered with legacy code. The tool was applied successfully to diagnose these problems.