Today was not fun 😩
Yeah, it was not fun but I did learn something. As I said yesterday, my main task now is to clearly define my goal or the anomalies I will be looking for by analyzing the logs. More than defining them, I have to answer the “how” question: how am I going to use the available information into the logs to detect my target anomalies?
Alright, now why was the day not fun? Well, I spent most of the day trying to understand the text in the logs. I can ensure you, it was not fun and it was the first time for me to do such activity.
However, it was not fun until I started understanding some outputs. 🙂 I was able to:
- distinguish disks and systems checks which were done periodically (per minute)
- distinguish what is recorded in the log file when a request in emitted either for Thor or Roxie.
- find the log file which registers the info about Roxie Queries run on WsECL (ESP.log)
With what I have learned today, I developed some ideas about anomalies I can target. For example, Roxie is said to be the Rapid Data Delivery Engine. Hence, I may look for queries which takes too much time by analyzing the running time of queries in the log file. My analysis should help me set the baseline of what is considered an appropriate running time and use that to outline “anomalous queries”.
That is currently one of my ideas. I have to clarify everything tomorrow and format it well in a document which I will submit to my mentors for review. I do feel better than yesterday.
Hopefully, I am heading the right way 😉