1

我有一个日志文件,其中包含以下数据:

2012-05-23T20:52:11+00:00 heroku[router]: GET myapp.com/practitioner_activities/10471/edit dyno=web.2 queue=0 wait=0ms service=866ms status=200 bytes=48799
2012-05-23T20:52:46+00:00 heroku[router]: GET myapp.com/users/sign_out dyno=web.1 queue=0 wait=0ms service=20ms status=302 bytes=88
2012-05-23T20:52:46+00:00 heroku[router]: GET myapp.com/ dyno=web.13 queue=0 wait=0ms service=18ms status=200 bytes=4680
2012-05-23T20:53:04+00:00 heroku[router]: POST myapp.com/p/ENaCXExu7qNEqzwYYyPs dyno=web.5 queue=0 wait=0ms service=207ms status=302 bytes=119
2012-05-23T20:53:04+00:00 heroku[router]: GET myapp.com/practitioner_activities/welcome dyno=web.3 queue=0 wait=0ms service=57ms status=200 bytes=5061
2012-05-23T20:53:04+00:00 heroku[router]: GET myapp.com/assets/application-print-715276cc0b76d0d82db3ab5866f22a23.css dyno=web.14 queue=0 wait=0ms service=9ms status=200 bytes=76386

我想解析它们并将它们转储到我可以用excel打开的文件中进行分析。我需要小时、分钟、动词(GET 或 POST)、url 和 'service=' 时间。

例如,对于上面的第一行:

2012-05-23T20:52:11+00:00 heroku[router]: GET myapp.com/practitioner_activities/10471/edit dyno=web.2 queue=0 wait=0ms service=866ms status=200 bytes=48799

我希望输出看起来像:

"20", "52", "GET", "myapp.com/practitioner_activities/10471/edit", "866"

我将如何awk使用简短的 ruby​​ 脚本或使用简短的 ruby​​ 脚本来执行此操作?

4

2 回答 2

3

使用awk,您可以尝试以下操作:

awk '{ OFS="\", \""; split ($8, array, "="); printf "\"" substr ($1 , length ($1) - 13, 2 ) OFS substr ($1 , length ($1) - 10, 2 ) OFS $3 OFS $4 OFS substr (array[2], 0, length (array[2]) -2) "\"\n" }' file.txt

结果:

"20", "52", "GET", "myapp.com/practitioner_activities/10471/edit", "866"
"20", "52", "GET", "myapp.com/users/sign_out", "20"
"20", "52", "GET", "myapp.com/", "18"
"20", "53", "POST", "myapp.com/p/ENaCXExu7qNEqzwYYyPs", "207"
"20", "53", "GET", "myapp.com/practitioner_activities/welcome", "57"
"20", "53", "GET", "myapp.com/assets/application-print-715276cc0b76d0d82db3ab5866f22a23.css", "9"

高温高压

编辑:

awk '{ OFS="\", \""; ORS="\"\n"; split ($8, array, "="); print "\"" substr ($1 , 12, 2 ), substr ($1 , 15, 2 ), $3, $4, array[2] + 0 }' file.txt

谢谢丹尼斯!代码现在好多了:-)

于 2012-05-23T21:54:11.813 回答
1

红宝石答案

ruby -ane '
    hr, min = $F[0][/(?<=T)\d\d:\d\d/].split(/:/)
    svc = $F[7].split(/=/)[-1]; svc[/ms/] = ""
    puts %q{"%d", "%d", "%s", "%s", "%d"} % [hr, min, $F[2], $F[3], svc]
' logfile
于 2012-05-24T00:49:57.370 回答