Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.

Support Log Parsing and Analysis Engine

The AI Security Analysis Engine is the primary diagnostic tool for this product. It produces a six-section report that covers jobs, pipeline logs and routing, agent health and per-agent logs, console logs, audit backlog, and storage health.

You can run it live against the current console, or against a backup archive from another system.

Run an Analysis​

  1. Confirm that the AI Security Analyzer JAR is installed. See AI Security Analyzer JAR.
  2. Select the Source: the live console, or a mounted backup archive. For a mounted archive, upload the archive.
  3. Set the Lookback window.
  4. Click Run Analysis.
  5. Open the result from the Analysis Runs table. See Analysis Runs.

Source​

SourceDescription
Live database (this console)Runs every section against the running databases and this console's own log files. Use it to triage the console you are logged in to.
Mounted backup archiveAnalyzes a .tar.gz file that Settings > Backup & Restore produced on a remote console. Upload the archive, then run the analysis.

Both modes use the AI Security Analyzer JAR for log-content analysis. See AI Security Analyzer JAR.

Live mode packages this console's logs into a temporary bundle and analyzes them. The logs are the backend, frontend, application, and agent dashboard logs, their rotated archives, and the log archive that every pipeline agent pushes. Live runs therefore report log-signature findings and per-agent log hotspots for the linguistic coherence (LC), extraction, and classification agents.

Mounted mode extracts the archive, restores its database dump into a temporary schema, and runs the analysis against the restored data and logs. It also scans every file in the archive for known error signatures. If the archive has no database dump, or the analyzer cannot connect, the sections that depend on it show a notice that explains why instead of rendering empty.

Mounted mode takes from a few seconds to a minute, depending on archive size. Live mode typically returns in under one second.

note

Sections B and F, the saturation query in Section C, and the PVC backlog in Section E always read this console's live ClickHouse data, in both modes. Backup archives never contain ClickHouse data, so analyzing an archive does not change where this data comes from. These sections are unavailable only if the console has no ClickHouse configured.

Lookback window​

The Lookback window sets how many hours of recent activity the time-bounded sections include: Sections A, B, C (saturation and offline episodes), D, and E. See The Six Sections. Default: 24 hours. Range: 1 to 720 hours. It applies to both Live and Mounted runs.

The Six Sections​

Section A: Job Analysis​

  • Job status counts, and median and 95th-percentile duration per job type.
  • Top error clusters.
  • The ingestion job family: PowerScale audit ingest, K8s scan, ECS SSH ingest, and RunAI usage ingest.
  • Recent Data Exposure Risk Processing runs.

Section B: Pipeline Log Analysis​

  • Pipeline log entries clustered by error kind and component, for any error kind that occurred 5 or more times.
  • Any agent whose error ratio exceeds 10% over the window.
  • Routing forensics: failed dispatch attempts grouped by failure reason, and a tally of routing outcomes (routed, no worker slots, PUT 503, failed). The routing rows explain why extraction work was not dispatched, without access to the live AI Risk Pipeline > Routing tab.

Section C: Agent Health​

  • Registered agents and heartbeat age.
  • Saturation episodes, when an agent reported ingress back-pressure.
  • Offline episodes from the agent dashboard log, with duration and recovery time.
  • The agent log inventory and hotspots. Each LC, extraction, and classification agent pushes its own logs to the console. Each log is parsed to show the agent name, pipeline stage, hostname, lines scanned, and recurring ERROR, WARNING, and CRITICAL signatures.

Section D: Console Logs​

  • ERROR and WARN hotspots from backend.log, the console application log, and its rotated history, for any signature that occurred 10 or more times.
  • Hotspots from frontend.log (browser-side client errors), grouped by the page URL that produced them.
  • Active alarms.
  • Log Signature Findings, which match every known error signature across every file in the dataset. Examples are out-of-memory errors, connection refused, raised alarms, pipeline stage-down codes, and CUDA out-of-memory.

Section E: Audit and Ingest Backlog​

  • The latest event per source type and how many minutes the ingest is behind real time. Ingest more than 60 minutes behind is flagged as STALLED.
  • Staleness of the PowerScale and ECS discovery watermarks.

Section F: Data Storage Health​

  • Per-table size, number of parts, and disk usage. Tables over 100 GB or 10,000 parts are flagged as unhealthy.
  • Pending ClickHouse mutations.

The file named application.log is a periodic JSON health-snapshot stream, not a standard application log. It is signature-scanned in Section D but has no hotspot analysis of its own.

Read the Result​

Each section appears as a table with a row-count badge in its header. A grey unavailable row means the section is degraded. This usually happens in Mounted mode for a section that depends on ClickHouse, because ClickHouse data is not part of a backup archive. Live mode sees everything.

Analysis Runs​

Every run is saved and remains available after a console restart. The Analysis Runs table below the Run Analysis button lists every run.

ColumnDescription
Run IDClick to reopen the result of that run.
ModeLIVE or MOUNTED.
StatusQueued, Running, Complete, or Failed.
ReportFor a Complete run, click HTML to download a self-contained HTML report (aisec-analysis-<runId>-<timestamp>.html). It contains every section's table, color-coded status badges, and any degradation notices, and is safe to share with engineering.
AgeTime since the run was submitted.
DeleteRemoves the run and its report files. For a Mounted run, it also removes the temporary schema.

Reopening a run is instant, because the console keeps the results and does not query again.

AI Security Analyzer JAR​

Both modes depend on the AI Security Analyzer JAR (argus-security-analyzer.jar). The AI Security Analyzer JAR panel in the same card shows whether the JAR is installed and its version, and lets an administrator upload or replace it.

ModeBehavior without the JAR
MountedThe run cannot start. Uploading an archive and clicking Run Analysis fails with an error that points to this panel.
LiveThe database sections still populate. Every log-content section is empty and shows a notice.

If a Live report lacks only its console-log and per-agent log sections, check this panel first.

Mounted Run Lifecycle​

For a Mounted run:

  1. The console stores the uploaded archive.
  2. The analyzer extracts the archive, restores the database dump into a temporary schema, runs the analysis queries, and scans every file for known error signatures.
  3. The console writes the HTML and JSON reports.
  4. The temporary schema is dropped automatically, whether the run succeeds or fails.
  5. After a successful run, the uploaded archive is deleted immediately. After a failed run, it is kept for one hour for debugging and then removed by the nightly cleanup.

The cleanup can drop only the temporary schemas it created for analysis runs. It cannot drop any other schema.

Report Retention​

Report Retention at the bottom of the AI Security Analysis Engine card sets how many days run reports stay on the console. Range: 1 to 365 days. Default: 30 days.

A nightly cleanup removes:

  • Report files older than the retention period
  • Run records older than the retention period
  • Uploaded archives left over from interrupted runs that are older than one hour
  • Temporary analysis schemas whose run no longer exists

This setting is saved separately from the global settings, so it cannot affect passwords or other tabs.

Security​

The report always redacts secret fields. Passwords, tokens, and API keys are replaced with [REDACTED] before they are written to the report. The raw backup archive never leaves the server. Only the HTML report is returned to the browser.