LogCluster

LogCluster is an experimental Perl-based tool for log file clustering and mining line patterns from log files. The development of LogCluster was inspired by SLCT, but LogCluster includes a number of novel features and data processing options.

LogCluster is distributed under the terms of GNU GPL, with the latest version being 0.08 (released in April 4, 2016).

In order to install LogCluster, copy the 'logcluster.pl' file from the distribution to the appropriate directory. Execute logcluster.pl --help for getting detailed help on usage and command line options.

A detailed discussion of the LogCluster algorithm and its application for security log analysis can be found in papers published at CNSM 2015 and MILCOM 2016.