Master Thesis: LLM-based log processing and Anomaly Detection in Cloud Orchestartion Systems
About this opportunity
Large-scale cloud orchestration systems continuously generate vast volumes of log data from services responsible for managing compute, network, and storage resources. These logs contain valuable information about system health, service degradation, and emerging failures. Detecting and diagnosing such issues at an early stage is essential for maintaining reliable services and a positive user experience. In this thesis, you will investigate whether a Large Language Model (LLM) can perform log processing and anomaly detection as effectively as a traditional approach based on log parsing, such as LogDrain or Drain, combined with Machine Learning (ML) techniques. The work will focus on a complex, distributed cloud orchestration environment. Relevant examples include OpenStack and Kubernetes, although the specific target system will be selected in consultation with the thesis supervisor.
What you will do
The thesis will investigate how LLM-based approaches compare with conventional log-processing and ML pipelines in terms of: Identifying normal and healthy system behaviour. Detecting anomalous events and service degradation. Classifying and characterising fault scenarios. Identifying likely error causes or affected services. Accuracy, robustness, scalability, and computational cost.
As part of the thesis, you will:
Study relevant research on log parsing, anomaly detection, fault diagnosis, and LLM-based analysis of operational data.
Establish a representative baseline for healthy operation by collecting and analysing logs from the target system under normal conditions.
Design and implement one or more conventional log-processing pipelines using log parsing and ML techniques.
Design and implement an LLM-based approach for log processing and anomaly detection.
Define, construct, and inject representative fault scenarios into the target environment.
Evaluate how well the different approaches detect anomalies, identify fault types, and determine probable root causes.
Analyse the results and assess the practical applicability of LLMs for monitoring large-scale distributed systems.
The skills you bring
Ongoing Msc studies within Computer Science, Electrical Engineering, Physics or Maths
Knowledge of LLMs, AI, ML, Cloud
Expected outcome
The thesis will provide a systematic comparison of LLM-based and traditional approaches to log analysis. It will identify the strengths and limitations of each approach and provide recommendations for using LLMs in the monitoring and diagnosis of distributed cloud orchestration systems.
Suggested research question How effectively can an LLM process logs, detect anomalies, and support fault diagnosis in a distributed cloud orchestration system compared with a conventional pipeline based on log parsing and Machine Learning?
Skills Required
- Currently pursuing a Master's degree in Computer Science, Electrical Engineering, Physics, or Mathematics
- Knowledge of large language models
- Knowledge of artificial intelligence
- Knowledge of machine learning
- Knowledge of cloud computing
What We Do
Ericsson builds the digital connectivity the world relies on. Our technology underpins the mobile networks, platforms, and systems that billions of people, businesses, and societies depend on every day. We are a global leader in communications technology, delivering mobile network infrastructure, cloud software, and wireless connectivity solutions for service providers and enterprises worldwide. Our networks support connectivity across 180+ countries, helping power everyday communication as well as critical digital services at global scale. Connectivity has evolved far beyond consumer mobile use. Today, nearly 80% of the world’s population accesses the internet via mobile networks, and Ericsson is helping shape what comes next. We are advancing 5G and 5G Advanced, developing network APIs that open connectivity to the global developer ecosystem, and applying automation and AI to make networks more intelligent, efficient, and resilient. Ericsson was the first company to launch live 5G networks on five continents, and our 5G platform is now commercially live in 150+ networks across 60+ countries. We also support more than 36,000 enterprise customers, enabling secure, high-performance connectivity for industries such as manufacturing, aviation, logistics, utilities, and public safety, where reliability and performance are mission critical. Innovation is central to how we work. Ericsson has approximately 28,000 employees in research and development, backed by one of the strongest intellectual property portfolios in the industry with 60,000+ granted patents. Our engineers, researchers, and technologists work across 100+ global R&D sites, helping define how networks evolve and how digital infrastructure is built for the long term. As the world moves toward a mobile-first, AI-powered, and cloud-driven future, connectivity becomes the foundation for digital transformation across every industry. Ericsson is building that foundation, shaping the future of digital connectivity through technology that operates at global scale and supports real-world impact, today and for what comes next.
Why Work With Us
Ericsson is a place for people who want to work on technology that powers everyday life. You’ll contribute to large-scale systems used every day, tackle complex challenges in live environments, and keep developing your skills and career in your own vision.
Gallery
Ericsson Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
Ericsson adopts a hybrid work model globally because we know balance matters. Sometimes things are better in real life. Other times we can be more productive at home. Our hybrid approach gives you the best of both worlds.






.png)










.png)









