LogParser查询报错:期望FROM关键字而非TO_TIMESTAMP token的技术求助
Fixing LogParser Syntax Error When Filtering Logs by Date Range
Let's break down what's causing your error and how to fix it step by step:
Key Issues in Your Original Query
- Incorrect placement of the
USINGclause: LogParser expects theUSINGkeyword to come before theFROMclause, not inside theSELECTstatement. Your current code tries to useUSINGas part of selecting columns, which violates LogParser's SQL syntax rules. - Using a column alias in the
WHEREclause: TheLocalDateTimealias you define in theSELECTisn't available to theWHEREclause—sinceWHEREexecutes beforeSELECT, the engine doesn't recognize the alias yet.
Corrected Query for LogParser Studio
SELECT TO_TIMESTAMP(date, time) AS LocalDateTime INTO OUTPUT.CSV FROM '[LOGFILEPATH]' WHERE TO_TIMESTAMP(date, time) BETWEEN TIMESTAMP ('2012-01-06 13:50:00', 'yyyy-MM-dd hh:mm:ss') AND TIMESTAMP ('2012-01-07 14:00:00', 'yyyy-MM-dd hh:mm:ss') ORDER BY LocalDateTime DESC
Corrected Query for Command Line LogParser 2.2
Replace the log path placeholder with your actual path, and make sure to escape any special characters if needed:
logparser.exe "SELECT TO_TIMESTAMP(date, time) AS LocalDateTime INTO OUTPUT.CSV FROM \inetpubs\logs\b\*.log WHERE TO_TIMESTAMP(date, time) BETWEEN TIMESTAMP ('2012-01-06 13:50:00', 'yyyy-MM-dd hh:mm:ss') AND TIMESTAMP ('2012-01-07 14:00:00', 'yyyy-MM-dd hh:mm:ss') ORDER BY LocalDateTime DESC"
Alternative: Using a Subquery (For Readability)
If you want to avoid repeating the TO_TIMESTAMP function, you can wrap the date conversion in a subquery. This works because the outer query can reference aliases from the inner subquery:
SELECT LocalDateTime INTO OUTPUT.CSV FROM ( SELECT TO_TIMESTAMP(date, time) AS LocalDateTime FROM '[LOGFILEPATH]' ) AS LogWithDateTime WHERE LocalDateTime BETWEEN TIMESTAMP ('2012-01-06 13:50:00', 'yyyy-MM-dd hh:mm:ss') AND TIMESTAMP ('2012-01-07 14:00:00', 'yyyy-MM-dd hh:mm:ss') ORDER BY LocalDateTime DESC
Quick Notes
- Make sure your log files actually have
dateandtimecolumns (standard for IIS logs, which your path suggests you're using). - If you're dealing with 24-hour time, use
HHinstead ofhhin your timestamp format string to avoid AM/PM confusion.
内容的提问来源于stack exchange,提问作者buck1112
相关产品推荐
相关产品推荐

