August 2026Unreviewed
From Noise to Signal: Improving Security Log Anomaly Detection Using LLMs with Endpoint-Specific Logs
Christopher Henshaw, Gour Karmakar
Abstract
Existing approaches to anomalous behaviour log detection, such as Wazuh rely primarily on predefined detection rules, while statistical anomaly detection approaches such as OpenSearch identify deviations from previously observed behavioural patterns. Recent research has investigated LLMs for log anomaly detection because of their ability to interpret semantic and contextual information. However, LLM-based approaches can be affected by prompt construction, noisy log data, and reliance on generic
Categories
Cite
@misc{henshaw2026from,
title = {{From Noise to Signal: Improving Security Log Anomaly Detection Using LLMs with Endpoint-Specific Logs}},
author = {Christopher Henshaw and Gour Karmakar},
year = {2026},
month = aug,
eprint = {2608.19938},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2608.19938}
}