Skip to content

Release-Aware Prior-Guided Regex Planning for Token-Bounded Log Retrieval in AIOps

Sep 2026 · International Symposium on Networks, Computers and Communications · pp. 1-6 · 0 citations · 18 references

Abstract

Large language models are increasingly being explored for incident triage and root-cause analysis in AIOps, but their practical use in cloud operations is constrained by the volume of logs produced during incident windows. In large distributed systems, a single fault can generate hundreds of thousands of log messages across services, dependencies, and infrastructure layers, making it infeasible to forward raw evidence directly to a reasoning model without exceeding token budgets and obscuring salient signals. This paper presents a release-aware, prior-guided, token-aware log retrieval framework that reduces the search space before downstream LLM reasoning. The central idea is to treat log retrieval as a planning problem rather than a purely generative task. The method constructs lightweight release-specific priors from deployment-time keyword harvesting and runtime support statistics, uses incident and observability context to narrow the likely fault space, and generates regex candidates that are evaluated not only for semantic relevance but also for their ability to partition the candidate log set under execution and token-cost constraints. A Split-Cost scoring rule supports iterative pruning until the retained evidence fits the downstream budget. Results from a controlled cloud simulation suggest that the proposed retrieval layer preserves most injected fault evidence while reducing log volume by nearly three orders of magnitude. More broadly, the framework addresses a key challenge in cloud-native AIOps: deciding which logs are worth reasoning over before reasoning begins.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.