Lnav自定义格式无法识别警告日志行的解决方法及预定义格式咨询
Your custom lnav format isn't picking up the warning lines because the regex pattern for warning_header doesn't match the actual structure of your log entries. Let's break down the problem and apply a working fix.
The Root Cause
Looking at your warning log lines:
WARNING Aug 18, 2025 9:33:43 PM 289ms:PROCESS_SHUTDOWN (stderr) (3984023):TransitionProcess.PROCESS_SHUTDOWN (PROCESS_SHUTDOWN) SIOCDELRT: No such process
Your original warning_header regex stops matching after capturing the logger field, but the actual line has an extra colon and message content after TransitionProcess.PROCESS_SHUTDOWN. Additionally, the multiline rule you added doesn't apply here since all warning lines are standalone entries, not folded indented lines.
Working Fixed Format
Replace your existing format with this updated version:
{ "$schema": "https://lnav.org/schemas/format-v1.schema.json", "dynac_transition": { "title": "Dynac Transition/Shutdown", "description": "Parses ++++++++ transition lines and WARNING blocks; correctly identifies warning-level PROCESS_SHUTDOWN entries.", "regex": { "transition_line": { "pattern": "^(?<timestamp>\\w{3} \\d{1,2}, \\d{4} \\d{1,2}:\\d{2}:\\d{2} [AP]M) (?<msec>\\d{3})ms \\+{6,} (?<message>.*)$", "timestamp-field": "timestamp", "timestamp-format": "%b %d, %Y %I:%M:%S %p", "level": "info" }, "warning_header": { "pattern": "^WARNING (?<timestamp>\\w{3} \\d{1,2}, \\d{4} \\d{1,2}:\\d{2}:\\d{2} [AP]M) (?<msec>\\d{3})ms:(?<context>[^:]+):(?<logger>[^:]+):(?<message>.*)$", "timestamp-field": "timestamp", "timestamp-format": "%b %d, %Y %I:%M:%S %p", "level": "warning" } }, "level": { "error": "ERROR", "warning": "WARNING", "info": "INFO", "debug": "DEBUG" }, "value": { "context": { "kind": "string" }, "logger": { "kind": "string", "identifier": true }, "msec": { "kind": "integer" }, "message": { "kind": "string" } }, "sample": [ { "line": "Aug 18, 2025 10:01:01 PM 093ms ++++++++ Terminating process TomcatMonitor." }, { "line": "Aug 18, 2025 10:01:01 PM 110ms ++++++++ Critical process MapServer terminated with exit value 143." }, { "line": "WARNING Aug 18, 2025 10:01:01 PM 128ms:PROCESS_SHUTDOWN (stderr) (3984160):TransitionProcess.PROCESS_SHUTDOWN: (PROCESS_SHUTDOWN) SIOCDELRT: No such process" } ] } }
Key Changes Made
Fixed
warning_headerRegex- Added
:(?<message>.*)$to capture the full warning message after the final colon in the line. - Adjusted the
loggercapture group to[^:]+to correctly grabTransitionProcess.PROCESS_SHUTDOWNbefore the final colon. - This ensures the entire warning line is matched and parsed correctly.
- Added
Removed Invalid Multiline Rule
- Your log doesn't have indented lines starting with
(PROCESS_SHUTDOWN)that need folding, so this rule was unnecessary and could interfere with matching. If you later encounter actual multiline logs, you can re-add and adjust this rule to match the real line prefixes.
- Your log doesn't have indented lines starting with
Updated Sample Warning Line
- Modified the sample to match the actual structure of your warning logs, helping lnav validate the format correctly.
How to Test
- Save the updated format as
dynac_transition.json. - Place it in lnav's format directory (typically
~/.lnav/formats/installed/). - Run
lnav your_log_file.log— your warning lines should now be marked with the warning level (usually yellow in the UI) and all fields will be properly parsed.
There isn't a pre-defined lnav format for Dynac Transition logs that I'm aware of, so this adjusted custom format is the best solution for your use case.
内容的提问来源于stack exchange,提问作者Álvaro

