Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
41 commits
Select commit Hold shift + click to select a range
6054316
add documentation updated with clean prek
Leokaufi Sep 15, 2026
955e2ec
fix flake8 mistakes
Leokaufi Sep 17, 2026
b2a2153
fix end of file errors
Leokaufi Sep 19, 2026
8d444ab
split detector specific configurations from common ones; unite FromTo…
Leokaufi Sep 22, 2026
c94448f
Merge remote-tracking branch 'origin/development' into update_docs_leo
Leokaufi Sep 23, 2026
4426a82
implement requested changes from this PR
Leokaufi Sep 23, 2026
996bebe
update the CorParserConfig with the Field functions
Leokaufi Sep 23, 2026
f6a7742
update auto_parser.md and autoparser.py with the Field function and t…
Leokaufi Sep 23, 2026
aecb9b6
update drain parser with automatic config args collection for the doc…
Leokaufi Sep 23, 2026
50eca73
Let EventSequenceDetector auto-configure under the configured classif…
viktorbeck98 Sep 23, 2026
4d6132d
update json parser with the automated config args getting function fo…
Leokaufi Sep 23, 2026
fccbf0a
update logbatcher_parser.md and parser.py with the Field function and…
Leokaufi Sep 23, 2026
5110d0b
update template_tree_matcher_parser.md and tree_matcher.py with the F…
Leokaufi Sep 23, 2026
e4bc9ec
forgot to change --8<-- mistakes
Leokaufi Sep 23, 2026
e549a48
update template_matcher.md and _parser.py with the Field function and…
Leokaufi Sep 23, 2026
e9adb75
automate writing common config arguments from parsers into the docume…
Leokaufi Sep 24, 2026
75f5051
automate writing parser arguments into the documentation
Leokaufi Sep 24, 2026
c6f4127
last polish before first PR
Leokaufi Sep 24, 2026
e66e6fa
add pre config hook for magled MKDocs snippet
Leokaufi Sep 24, 2026
6351491
fix imports and project root mistakes
Leokaufi Sep 24, 2026
ba3d038
Skip configure and set_configuration while auto_config is False
viktorbeck98 Sep 24, 2026
34e5b80
Raise PersistencySaveError when PersistencySaver.save() fails
viktorbeck98 Sep 24, 2026
b3142c3
Remove unnecessary docstring from StabilityAutoConfigParams
viktorbeck98 Sep 24, 2026
d8ed843
Merge pull request #322 from ait-detectmate/fix/319-persistency-save-…
viktorbeck98 Sep 27, 2026
336c363
list every config argument in the docs, addressing PR review
viktorbeck98 Sep 29, 2026
ede8a26
show minimal, runnable YAML configs in the component docs
viktorbeck98 Sep 29, 2026
7eda4b1
make detector and parser names consistent across the docs
viktorbeck98 Sep 29, 2026
f516022
Merge pull request #317 from ait-detectmate/fix/event-sequence-classi…
viktorbeck98 Sep 29, 2026
5ad7ba1
Merge pull request #321 from ait-detectmate/fix/auto-config-gates-con…
viktorbeck98 Sep 29, 2026
ce644e5
add a commit changes in the pipeline
ipmach Sep 29, 2026
ac6a919
Merge remote-tracking branch 'origin/development' into update_docs_leo
viktorbeck98 Sep 29, 2026
7cc8cba
remove combo table to test pipeline
ipmach Sep 29, 2026
85671fc
Merge branch 'update_docs_leo' of github.com:ait-detectmate/DetectMat…
viktorbeck98 Sep 29, 2026
15bea76
test pipeline now
ipmach Sep 29, 2026
41e3263
lets try again :)
ipmach Sep 29, 2026
4b6fab0
Automated update
github-actions[bot] Sep 29, 2026
435171a
correct pipeline
ipmach Sep 29, 2026
4f3cdc8
test again combo
ipmach Sep 29, 2026
6ebbfbd
Automated documentation update
github-actions[bot] Sep 29, 2026
0cb483e
Merge pull request #301 from ait-detectmate/update_docs_leo
viktorbeck98 Sep 29, 2026
877c08d
to 0.6.0
ipmach Sep 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 19 additions & 1 deletion .github/workflows/python-app.yml
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ on:
pull_request:

permissions:
contents: read
contents: write

jobs:
build:
Expand All @@ -23,6 +23,10 @@ jobs:
activate-environment: true
enable-cache: true

- uses: actions/checkout@v6
with:
ref: ${{ github.event.pull_request.head.ref }}

- name: Set timezone
run: sudo timedatectl set-timezone Europe/Vienna

Expand All @@ -32,6 +36,20 @@ jobs:
- name: Test with pytest
run: uv run pytest -s --run-ignored

- name: Commit and Push Changes
env:
PR_BRANCH: ${{ github.event.pull_request.head.ref }}
run: |
git add .
if git diff --cached --quiet; then
echo "No tracked files changed"
exit 0
fi
git config user.name "github-actions[bot]"
git config user.email "41898282+github-actions[bot]@users.noreply.github.com"
git commit -m "Automated documentation update"
git push origin "HEAD:$PR_BRANCH"

# integration tests for DetectMateService
- name: Checkout DetectMateService
uses: actions/checkout@v4
Expand Down
10 changes: 10 additions & 0 deletions .pre-commit-config.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -73,3 +73,13 @@ repos:
hooks:
- id: python-check-blanket-noqa
- id: python-no-log-warn

# Repair mangled MkDocs snippet includes (`--8 < --"docs` -> `--8<-- "docs`)
- repo: local
hooks:
- id: fix-snippet-markers
name: fix mkdocs snippet markers
language: system
entry: sed -i -E
args: ['s/--8 *< *-- *"docs/--8<-- "docs/g']
files: ^docs/.*\.md$
42 changes: 42 additions & 0 deletions docs/advanced/overall_architecture.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,42 @@
# Overall architecture

## How things work and where data goes

This document describes the high-level design of the DetectMateLibrary, how components interact, the data contracts they use, and guidance for deploying and extending the system. The library is built around small, composable components that operate on streaming log data and exchange strongly-typed Schema objects.

Key goals:

- Clear separation of concerns (reading, parsing, detection, output).
- Stream-friendly processing with minimal buffering.
- Well-defined schema contracts so components can be composed or run as microservices.
- Easy extensibility: add new readers, parsers or detectors by subclassing core base classes.

## Components flow

The pipeline is strictly directional:

- Parser: consumes raw logs and produces parsed log objects (structured fields, timestamps, variables).
- Detector: consumes parsed logs and generates alerts/findings when rules or models match anomalous behavior.
- Alert Aggregation: consumes alerts and aggregates them.

Each arrow represents a stream of Schema objects. Components are designed to run in the same process for lightweight setups or as separate services for scalable deployments.

![Components flow](../img/diagrams_structure.png)

## Components architecture

All components inherit from a `CoreComponent` class. This class provides all the essential functionality required for DetectMate to operate (see UML diagram below). Every `Detector` must inherit from `CoreDetector`, every `AlertAggregator` must inherit from `CoreAlertAggregation` and every `Parser` must inherit from `CoreParser` to ensure compatibility with DetectMate.

Each component's arguments must be stored in its corresponding configuration class. These config classes follow the same design pattern as their components and must inherit from `CoreConfig`.

![Architecture](../img/uml_structure.png)

## Components methods

Each Core* base class exposes a small, stable API that implementations must implement or may override.

```python
--8<-- "docs/examples/others/components_methods.py:read"
```

Go back [Index](../index.md)
2 changes: 1 addition & 1 deletion docs/alert_aggregator.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ This document explains expected APIs, how to implement a parser, testing tips an
- `CoreParser.run()` handles lifecycle and calls `aggregate_alerts()` for each input; implement pure alert aggregation logic inside `aggregate_alerts()` where possible.
- Use a typed `Config` class (subclass of `CoreAlertAggregationConfig`) to hold runtime parameters.

## CoreParser — minimal API
## CoreParser -- minimal API

Recommended signatures and behavior:

Expand Down
29 changes: 18 additions & 11 deletions docs/auxiliar/persistency.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,20 +31,20 @@ Two families ship today:
raw rows. Very storage heavy and *not recommended* for production-ready detectors.
- **Tracker backends** (`EventStabilityTracker`) keep only derived features
(e.g. "this variable has been constant for the last 10k events") that are relevant for the detector. Use these
when you only need a summary or a subset of the log's information, not the raw history — they cost a fraction of
when you only need a summary or a subset of the log's information, not the raw history -- they cost a fraction of
the memory.

All backends implement the same four-method contract: `add_data`, `get_data`,
`dump`, `load`. That contract is what `EventPersistency` and
`PersistencySaver` rely on — anything you add later only has to follow it.
`PersistencySaver` rely on -- anything you add later only has to follow it.

### 3. Saver lifecycle (`PersistencySaver`)

`EventPersistency` itself is in-memory. To survive a process restart, the
state has to be written somewhere. `PersistencySaver` wraps an
`EventPersistency` and:

- writes to disk (or any `fsspec` URI) on two triggers — a wall-clock interval
- writes to disk (or any `fsspec` URI) on two triggers -- a wall-clock interval
and an event-count threshold;
- optionally `auto_load`s previously saved state during construction;
- exposes `start()` / `stop()` so the background timer can be torn down
Expand Down Expand Up @@ -108,10 +108,10 @@ ep[event_id] # alias for get_event_data
| Class | Use when |
|---|---|
| `persistency.EventDataFrame` | You need history and a Pandas DataFrame is the natural shape. |
| `persistency.ChunkedEventDataFrame` | High-volume / streaming workloads — Polars-backed with row-retention and automatic compaction. |
| `persistency.ChunkedEventDataFrame` | High-volume / streaming workloads -- Polars-backed with row-retention and automatic compaction. |
| `persistency.EventStabilityTracker` | You only care about how variables behave over time (`STATIC` / `STABLE` / `UNSTABLE` / `RANDOM`). Cheapest memory footprint. |

All three are re-exported from the top of the package — `persistency.X` is the
All three are re-exported from the top of the package -- `persistency.X` is the
canonical import; the deeply nested submodules are an implementation detail.

### Persisting to disk
Expand All @@ -134,7 +134,14 @@ saver.stop() # final flush, stops the background timer

`PersistencySaver.save()` is thread-safe, and `stop()` is idempotent. The two
save triggers (`save_interval_seconds` and `events_until_save`) are
independent — whichever fires first wins.
independent -- whichever fires first wins.

If writing to storage fails (unwritable path, full disk, lost credentials),
`save()` and `stop()` raise `persistency.PersistencySaveError`, and
`events_since_save` keeps counting the unsaved events. Saves fired by the two
triggers cannot raise to a caller, so they log the failure at `ERROR` instead;
the timer keeps running, and after a failed save the event-count trigger waits
another `events_until_save` events before retrying.

#### Restoring state

Expand All @@ -147,21 +154,21 @@ saver = persistency.PersistencySaver(
```

If `auto_load=True` and no saved state exists, the constructor raises
`persistency.PersistencyLoadError` immediately — fail-fast rather than
`persistency.PersistencyLoadError` immediately -- fail-fast rather than
silently starting empty.

#### Exporting and importing state on demand

For one-shot transfers — e.g. moving trained state to a new environment, or
taking a manual snapshot — use the standalone functions directly:
For one-shot transfers -- e.g. moving trained state to a new environment, or
taking a manual snapshot -- use the standalone functions directly:

```python
from detectmatelibrary.utils import persistency

# Export to a file URI
persistency.save(ep, "./snapshots/trained-state")

# Export to bytes (no disk I/O — useful when sending state over a network API)
# Export to bytes (no disk I/O -- useful when sending state over a network API)
data: bytes = persistency.save(ep)

# Import from a file URI
Expand All @@ -185,7 +192,7 @@ when a saver is active.
#### Detector-level export and import

When working through a detector (the typical path for DetectMateService), use
the methods on the detector object directly — no need to access
the methods on the detector object directly -- no need to access
`EventPersistency` internals:

```python
Expand Down
66 changes: 0 additions & 66 deletions docs/basic_idea.md

This file was deleted.

103 changes: 0 additions & 103 deletions docs/basic_usage.md

This file was deleted.

Loading
Loading