Many studies of system logs treat them as sources of failure events. Log analysis of system errors typically involves classifying log messages based on the preset severity level of the reported error, and on tokens and their positions in the text of the message [14] [11]. More sophisticated analysis has included the study of the statistical properties of reported failure events to localize and predict faults [15] [11] [9] and mining pat- terns from multiple log events [8]. Our treatment of system logs differs from such tech- niques that treat logs as purely a source of events: we impose additional semantics on the log events of interest, to identify durations in which.