Interpreting the Data: Parallel Analysis with Sawzall

| Posted in LMI and SIEM

Some one on the loganalysis mailing list posted a link to a Google Labs paper: Interpreting the Data: Parallel Analysis with Sawzall.

It talks about a distributed aggregation and filtering method using Google’s Sawzall interpreted language. Very interesting paper, the concept of applying distributed computing resources to do work in parallel is not new. LogLogic have implemented this concept to achieve massive parallelism and performance on log analysis for quite sometime now.

The interesting part of the paper relates to its new language, Sawzall. It’s a new language designed specifically for simplicity and parallelism.

First I don’t understand why they couldn’t have created Sawzall as a library for one of the existing languages such as Perl or Python. After some discussion with a Googler, I am somewhat convinced that there might be good reason for a new language. The main reason being parallelism. Most of the languages aren’t designed to program and execute in parallel from the ground up.

However, I have to nitpick the performance example they gave in the paper. The benchmark test cases are all CPU-bound cases. However, earlier in the paper, the authors talked about the applications for this language being mostly IO-bound. It would seem to make sense if they gave some examples that are IO-bound and still be able to show the performance advantage of Sawzall.

Another question I have is how much Sawzall relies on GFS. I am assuming that the parallel execution of Sawzall depends on many of the GFS features, but I have no basis for that.

February 20th, 2006 | Jian Zhen | No Comments

Security Log Management

Just picked up this book.

Security Log Management.

Will let you know how it reads.

February 13th, 2006 | Jian Zhen | 1 Comment

DEMO 2006: Podtech interview

| Posted in LMI and SIEM

Another bit of voice from DEMO 2006…An interview by Podtech…

February 11th, 2006 | Jian Zhen | No Comments

DEMO 2006: LogLogic Demo Audio

| Posted in LMI and SIEM

Here’s a MP3 of the LogLogic demo at DEMO 2006, courtesy of TJ’s Weblog. (I trimmed the MP3 to contain just the LogLogic portion, hope that’s ok with TJ. :) )

February 8th, 2006 | Jian Zhen | No Comments

Demo 2006: riya

| Posted in General Techologies

Now I think this is one of the kewlest companies I saw today.

It uses facial recognition to automatically tag photos that you have. Once you train riya, it goes through all your photos to auto-tag all other photos that have the same face that you used for training.

It also recognize text inside the photo as well.

Definitely wins my 2nd kewl demo award (after LogLogic of course).

February 7th, 2006 | Jian Zhen | No Comments

Demo 2006: Cnet coverage, etc

| Posted in General Techologies

Andy and I are roaming around demo..check out our picture. Cnet also has up to the min coverage.

Check out vivid sky, really kewl concept…sorry…too much to type on the lil treo keyboard..

More...
February 7th, 2006 | Jian Zhen | No Comments

Demo 2006 continues (tue)

| Posted in General Techologies

Ok so we have seen several demos today in the show, blurb, moobella, mp3cars, accomplice..etc..etc.
The only consistent theme I got so far is that none of these companies have really figured out how to make $$ yet. They are all here to debut their betas and seek funding.
Though I do see some interesting potentials…i can [...]

More...
February 7th, 2006 | Jian Zhen | No Comments

Demo 2006 continues

| Posted in General Techologies

Blogging from the treo for the first time, using wordpress’ blog-by-email feature. It’s quite a nifty setup.
It’s been a busy day here at demo 2006. Lots of rehersal and testing of the setup for tomorrow’s full day event.
Met some interesting companies today. Many are taking advantage of the web 2.0 hype to launch some nifty [...]

More...
February 6th, 2006 | Jian Zhen | No Comments

DEMO 2006

| Posted in General Techologies

Flew over here to sunny PHX on Sunday to attend the DEMO 2006 conference, the leading conference for launching new products and services.
It’s my first time attending the conference and it’s interesting to see how organized they want you to be when doing a demo. You must have the whole demo script ready and sent [...]

More...
February 6th, 2006 | Jian Zhen | No Comments

GLTerminal

| Posted in General Techologies

wow…this is really kewl!
It’s a terminal program for OS X that emulates to old amber or green terminals that I used back at Purdue!!
Running it on full screen on a small monitor would really make this a pretty awesome setup!

More...
February 4th, 2006 | Jian Zhen | No Comments