Solved

Cherry picking Log File entries

Posted on 2003-10-30
5
215 Views
Last Modified: 2010-03-04
Hi, to begin this is not homework.

I am attempting to delve into a logfiles whose formats are as follows..

xx.xx.153.22 - - [23/Oct/2003:05:42:50 -0700] "GET /img_/misc/ekbh.gif HTTP/1.1" 200 43 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; MSN 8.0; MSN 8.5; MSNbMSNI; MSNmen-us; MSNcIA)" 0
xx.xx.210.61 - - [23/Oct/2003:05:43:40 -0700] "GET /img_/misc/okil.gif HTTP/1.0" 304 - "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" 0

My wish is to pull from the logs the date, asset name (ekbh.gif), and the number of times that this asset has been called on that day. In my previous efforts at Perl I've been successful in getting browser info and which OS was used but this has stumped me. Can anyone help?

Thanks.

0
Comment
Question by:roodawg
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 28

Accepted Solution

by:
FishMonger earned 125 total points
ID: 9654633
I used two regexes to extract the date and file name, but it can also be done with a single (more complex) regex.

#!/usr/bin/perl -w

use Data::Dumper;

while (<DATA>) { # log file passed to the script via command line
   $date = $1 if (/\[([^:]+)/);
   $asset_name = $1 if (/([^\/]+)(?= HTTP)/);
   $assets{$date}{$asset_name}++;
}

print Dumper %assets;  # this was used as a debugging statement

for $key (keys %assets) {
   print "$key: ";
   for $value (keys %{$assets{$key}}) {
      print "$value=$assets{$key}{$value}\n";
   }
}


__DATA__
xx.xx.153.22 - - [23/Oct/2003:05:42:50 -0700] "GET /img_/misc/ekbh.gif HTTP/1.1" 200 43 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; MSN 8.0;MSN 8.5; MSNbMSNI; MSNmen-us; MSNcIA)" 0
xx.xx.210.61 - - [24/Oct/2003:05:43:40 -0700] "GET /img_/misc/okil.gif HTTP/1.0" 304 - "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" 0
xx.xx.153.22 - - [23/Oct/2003:05:42:50 -0700] "GET /img_/misc/ekbh.gif HTTP/1.1" 200 43 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; MSN 8.0;MSN 8.5; MSNbMSNI; MSNmen-us; MSNcIA)" 0
xx.xx.210.61 - - [24/Oct/2003:05:43:40 -0700] "GET /img_/misc/okil.gif HTTP/1.0" 304 - "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" 0
xx.xx.153.22 - - [23/Oct/2003:05:42:50 -0700] "GET /img_/misc/ekbh.gif HTTP/1.1" 200 43 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; MSN 8.0;MSN 8.5; MSNbMSNI; MSNmen-us; MSNcIA)" 0
xx.xx.210.61 - - [24/Oct/2003:05:43:40 -0700] "GET /img_/misc/okil.gif HTTP/1.0" 304 - "-" "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)" 0
0
 
LVL 28

Expert Comment

by:FishMonger
ID: 9654637
Here is the output from that script.  (the lines prior to the last 2 are from the debugging statement)

$VAR1 = '24/Oct/2003';
$VAR2 = {
          'okil.gif' => 3
        };
$VAR3 = '23/Oct/2003';
$VAR4 = {
          'ekbh.gif' => 3
        };
24/Oct/2003: okil.gif=3
23/Oct/2003: ekbh.gif=3
0
 
LVL 28

Expert Comment

by:FishMonger
ID: 9654651
I should have clarified one of those lines.

while (<DATA>) { # log file passed to the script via the __DATA__ section at the end of the script

while (<>) { # log file passed to the script via command line
0
 

Author Comment

by:roodawg
ID: 9655570
FM, thanks. This is a thing of beauty.

I should have mentioned that the logfiles are in the format of appserver.log.YYYY-MM-DD and reside in directories called appserv01, appserv02, appserv03, etc. My need is to have this script delve into each of the appservers (excluding any of the webserver directories). Oh and let's not for get formatting to a CSV file. As stated before I'm pretty new to all this and have done this in the past usint perl's opendir() and readdir() statements. I don't need code but by your experience is this the way to go?

Thanks
0
 
LVL 28

Expert Comment

by:FishMonger
ID: 9655796
I don't have enough info to say if your approach is the best method but it sounds fine.  One thing you may want to look at using is the File::Find module.

http://search.cpan.org/~jhi/perl-5.8.1/lib/File/Find.pm
0

Featured Post

Secure Your Active Directory - April 20, 2017

Active Directory plays a critical role in your company’s IT infrastructure and keeping it secure in today’s hacker-infested world is a must.
Microsoft published 300+ pages of guidance, but who has the time, money, and resources to implement? Register now to find an easier way.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

I have been pestered over the years to produce and distribute regular data extracts, and often the request have explicitly requested the data be emailed as an Excel attachement; specifically Excel, as it appears: CSV files confuse (no Red or Green h…
A year or so back I was asked to have a play with MongoDB; within half an hour I had downloaded (http://www.mongodb.org/downloads),  installed and started the daemon, and had a console window open. After an hour or two of playing at the command …
Explain concepts important to validation of email addresses with regular expressions. Applies to most languages/tools that uses regular expressions. Consider email address RFCs: Look at HTML5 form input element (with type=email) regex pattern: T…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question