Uppsats

Time Series Anomaly Detection for Server Monitoring Data Using Unsupervised Machine Learning

Master-uppsats

Linköpings universitet/Kommunikationssystem

Publicerad: 2026

Språk: Engelska

Sammanfattning

As digital infrastructure grows in scale and complexity, reliable server monitoring becomes increasingly critical. This is particularly important within healthcare IT systems, where a disruption can prevent clinical staff from being able to do their job. Traditional methods for anomaly detection include statistical techniques or a manually defined threshold, where both struggle to capture complex temporal patterns. They also require separate manual configurations for each monitored metric, something that is not scalable in large and diverse server infrastructures. This thesis investigates whether a single generalized unsupervised univariate machine learning model can detect anomalies across diverse server metrics in Sectra’s monitoring system without server-specific customization. To achieve this, a transformer autoencoder was developed and trained on data from 63 different hospitals, totalling more than 210 million data points. To find the best performing model, six configurations with varying hyperparameters were trained and evaluated. The best configuration was compared against the pretrained foundation model MOMENT in both zero-shot and fine-tuned settings, a static threshold classifier, and Claude Sonnet 4.6 as a large language model (LLM) baseline. In addition to the labeled evaluation, the best transformer autoencoder configuration and MOMENT variant were also tested in two practical scenarios: ranking metrics during known ongoing system problem periods and detecting behavioral changes following a system update. The best performing transformer autoencoder configuration achieved a weighted VUS-PR of 0.625 and a weighted PA-F1 of 0.912. With that, it outperformed both MOMENT and the LLM, while also being approximately 19 times faster than MOMENT at inference. In the applied scenarios, both models surfaced known problematic metrics, consistently ranking them in top positions, and identified post-update behavioral changes that had gone unnoticed through manual monitoring. The univariate approach proved well suited for Sectra’s diverse infrastructure, as it allowed a single model to generalize across different hospitals without requiring server specific customization. Future work includes expanding the labeled evaluation dataset, training a model on more data, further investigation of threshold strategies, and implementing relevance-based weighting of metrics to better prioritize alerts for support personnel.

Information

Lärosäte / institution
Linköpings universitet/Kommunikationssystem
Publiceringsdatum
2026
Uppsatstyp
Master-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.