A Lightweight Log Anomaly Detection System for Containerized Applications on Resource-Constrained Edge Devices

Dwiky Dimas Prihartomo, Danang Rimbawa H.A., Bisyron Wahyudi

Abstract


Log monitoring and anomaly detection are essential components in maintaining the reliability of containerized applications, particularly in resource-constrained edge environments. However, many existing log-based anomaly detection approaches rely on complex models that are difficult to deploy on low-power devices. This paper presents a lightweight log anomaly detection system designed for containerized applications running on edge devices with limited computational resources. The proposed system integrates containerized log collection, real-time traffic monitoring, and anomaly detection using simple statistical indicators as engineering tools. The system is implemented and evaluated on a Raspberry Pi-based platform using Dockerized services and four synthetic traffic scenarios: baseline, burst, drop, and traffic spike. Experimental results show that the proposed approach achieves a low false positive rate of 1.05% under normal workloads and successfully detects sustained traffic spikes with a detection latency of 69 seconds, while maintaining low computational overhead. The results also indicate that short-duration bursts may be partially absorbed by the EWMA-based baseline adaptation. Overall, the findings confirm that simple and interpretable detection mechanisms remain practical and effective for edge-based system monitoring, providing a feasible alternative to complex learning-based approaches in constrained environments.

Keywords


Z-score, log anomaly detection, edge computing, containerized systems, streaming analytics, EWMA.

Full Text:

PDF

References


D. Bernstein, “Containers and cloud: From LXC to Docker to Kubernetes,” IEEE Cloud Computing, vol. 1, no. 3, pp. 81–84, 2014.

J. Dean and L. A. Barroso, “The tail at scale,” Communications of the ACM, vol. 56, no. 2, pp. 74–80, 2013.

J. Liu, J. Huang, Y. Huo, et al., “Scalable and adaptive log-based anomaly detection with expert in the loop,” arXiv preprint arXiv:2306.05032, 2023.

J. Chen, W. Chong, S. Yu, et al., “TCN-based lightweight log anomaly detection in cloud-edge collaborative environment,” in Proc. IEEE Int. Conf. Blockchain, 2022, pp. 54–61.

W. Shi, J. Cao, Q. Zhang, Y. Li, and L. Xu, “Edge computing: Vision and challenges,” IEEE Internet of Things Journal, vol. 3, no. 5, pp. 637–646, 2016.

G. E. Farrel, W. Yahya, A. Basuki, et al., “Scalable edge computing cluster using a set of Raspberry Pi: A framework,” in Proc. ACM Int. Conf. Advanced Informatics, 2023, pp. 162–167.

J. Liu, J. Huang, Y. Huo, et al., “SeaLog: Scalable and adaptive log-based anomaly detection,” arXiv preprint arXiv:2306.05032, 2023.

R. Das and T. Luo, “LightESD: Fully-automated and lightweight anomaly detection framework for edge computing,” in Proc. IEEE Int. Conf. Edge Computing, 2023, pp. 178–185.

A. Oliner, A. Ganapathi, and W. Xu, “Advances and challenges in log analysis,” Communications of the ACM, vol. 55, no. 2, pp. 55–61, 2012.

F. T. Liu, K. M. Ting, and Z.-H. Zhou, “Isolation forest,” in Proc. IEEE Int. Conf. Data Mining, 2008, pp. 413–422.

M. Antonini, M. Vecchio, F. Antonelli, et al., “Smart audio sensors in the Internet of Things edge for anomaly detection,” IEEE Access, vol. 6, pp. 67594–67610, 2018.

Z. Tan, Q. Wang, C. Anagnostopoulos, et al., “LedLog: Lightweight explainable real-time dual-model log anomaly detection system,” SSRN Electronic Journal, 2024.

J. Ko and M. Comuzzi, “Online anomaly detection using statistical leverage for streaming business process events,” in Proc. Int. Conf. Advanced Information Systems Engineering, 2021, pp. 195–210.

D. C. Montgomery, Introduction to Statistical Quality Control, 7th ed. Hoboken, NJ: Wiley, 2013.

S. W. Roberts, “Control chart tests based on geometric moving averages,” Technometrics, vol. 1, no. 3, pp. 239–250, 1959.

B. Rosner, “Percentage points for a generalized ESD many-outlier procedure,” Technometrics, vol. 25, no. 2, pp. 165–172, 1983.

L. An, A.-J. Tu, X. Liu, et al., “Real-time statistical log anomaly detection with continuous AIOps learning,” in Proc. Int. Conf. Software Technologies, 2022, pp. 294–305.

“A controller for anomaly detection, analysis and management for self-adaptive container clusters,” International Journal on Advances in Systems and Measurements, vol. 12, no. 3&4, pp. 168–179, 2019.

Fluent Bit Documentation, “About Fluent Bit,” [Online]. Available: https://docs.fluentbit.io/




DOI: http://dx.doi.org/10.52155/ijpsat.v%25v.%25i.8530

Refbacks

  • There are currently no refbacks.


Copyright (c) 2026 Dwiky Dimas Prihartomo

Creative Commons License
This work is licensed under a Creative Commons Attribution 4.0 International License.