All evidence records

first-party · public-dataset study

Log triage: filtering is not automatically saving

Conservative triage can add cost; reuse may help more.

Jalil Laaraichi / jevlogs; same maintainer as System One Engine.

Evidence confidence

moderate. A described comparison supports a bounded conclusion. Workload transfer and independent reproduction remain unresolved.

What was observed

Select log records for deeper analysis while preserving originals.

2,500 HDFS and 2,500 BGL records; threshold, severity, cache and rule comparisons. Existing results inspected; no new rerun.

Baseline

Severity-only, keyword and exact-cache policies.

Finding

The conservative HDFS policy sent nearly everything for analysis. The modeled downstream bill increased rather than decreased. BGL recall was explained by deterministic FATAL protection.

  • HDFS anomaly recall 99.33%; only 0.84% routed away from deeper analysis.
  • Illustrative downstream cost change: +2.55%.
  • HDFS exact-cache hit rate 96.48%.

What the result does not establish

HDFS labels are block-level, not true line-level incident labels. The cost example assumes downstream token counts and prices, not actual billing. Upstream Loghub data has research/academic terms.

What we would test in System One

Expose triage alongside exact reuse and visible bypass rates. Compare simple severity rules first; never sell universal savings or discard original records.

This recommendation is our interpretation of the study. Related research does not establish the quality of every Engine recipe.

Try a related workflow

Primary sources

Read this record in System One Bench. Source commits are pinned where available. Review dates describe our inspection, not the original run date.

Metric definitions and review method · Submit a correction or new result