TY - GEN
T1 - LLM-based AIOps via Log Prioritization in Air-Gapped Systems
AU - Song, Sanghee
AU - Kim, Hwajung
N1 - Publisher Copyright:
© 2026 Copyright held by the owner/author(s).
PY - 2026/4/28
Y1 - 2026/4/28
N2 - Large-scale computing systems generate massive volumes of operational logs across diverse components. Although LLMs offer new opportunities for automated AIOps analysis, directly applying them to raw log streams is impractical due to input length and resource constraints, especially in air-gapped and edge environments. In this paper, we propose an LLM-based AIOps pipeline that converts raw logs into structured events through rule-based transformation and temporal aggregation. The structured events are then prioritized to enable efficient LLM-driven diagnosis. We implement the pipeline in a real-world isolated edge environment and evaluate it using production-scale system logs. Experimental results show that our pipeline enables efficient LLM-guided analysis while preserving system-level diagnostic effectiveness. Our pipeline reduces log volume by 76% through the log transformation stage. After aggregation into structured events, the log prioritization stage further reduces the event set by 51% before LLM analysis, resulting in a 43% reduction in LLM token requirements compared to the non-prioritized case, significantly lowering resource consumption in constrained environments.
AB - Large-scale computing systems generate massive volumes of operational logs across diverse components. Although LLMs offer new opportunities for automated AIOps analysis, directly applying them to raw log streams is impractical due to input length and resource constraints, especially in air-gapped and edge environments. In this paper, we propose an LLM-based AIOps pipeline that converts raw logs into structured events through rule-based transformation and temporal aggregation. The structured events are then prioritized to enable efficient LLM-driven diagnosis. We implement the pipeline in a real-world isolated edge environment and evaluate it using production-scale system logs. Experimental results show that our pipeline enables efficient LLM-guided analysis while preserving system-level diagnostic effectiveness. Our pipeline reduces log volume by 76% through the log transformation stage. After aggregation into structured events, the log prioritization stage further reduces the event set by 51% before LLM analysis, resulting in a 43% reduction in LLM token requirements compared to the non-prioritized case, significantly lowering resource consumption in constrained environments.
KW - AIOps
KW - Air-gapped systems
KW - Large language models
KW - Log analysis
KW - Log prioritization
KW - Log reduction
UR - https://www.scopus.com/pages/publications/105038687913
U2 - 10.1145/3805621.3807626
DO - 10.1145/3805621.3807626
M3 - Conference contribution
AN - SCOPUS:105038687913
T3 - EuroMLSys 2026 - Proceedings of the 2026 the 6th European Workshop on Machine Learning and Systems
SP - 426
EP - 432
BT - EuroMLSys 2026 - Proceedings of the 2026 the 6th European Workshop on Machine Learning and Systems
PB - Association for Computing Machinery, Inc
T2 - 6th Workshop on Machine Learning and Systems, EuroMLSys 2026
Y2 - 27 April 2026 through 30 April 2026
ER -