You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Grok表达式提取日志中的PID、QN、ET字段值?

Grok Pattern to Extract PID, QN, and ET from Your Log Entry

Let's start by zeroing in on the key segment of your log that holds the fields you need:

sys tmp usr var Purging cache - END (PID: 4477, QN: 51 / 51 , ET: 0 ) anaconda-post.log bin dev etc home lib lib64 lost+found media mnt opt

The Core Grok Pattern

Here's a tailored pattern that directly extracts your target fields:

Purging cache - END \(PID: %{NUMBER:pid:int}, QN: %{NUMBER:qn_current:int} / %{NUMBER:qn_total:int} , ET: %{NUMBER:et:int} \)

Breakdown of Each Component

Let's walk through how this works so you can tweak it if needed:

  • Purging cache - END \(: Matches the literal text right before your target fields. We escape the ( with a backslash because it's a special character in Grok syntax.
  • %{NUMBER:pid:int}: Grabs the PID value and stores it as an integer in a field named pid. Using :int ensures it's treated as a numeric value instead of a string.
  • , QN: : Matches the exact literal text between the PID and QN values.
  • %{NUMBER:qn_current:int} / %{NUMBER:qn_total:int}: Since your QN is formatted as current / total, this extracts both numbers as separate integer fields (qn_current and qn_total)—way more useful than grabbing the whole string if you need to do calculations later.
  • , ET:: Matches the literal text between the QN section and ET value.
  • %{NUMBER:et:int}: Extracts the ET value as an integer, storing it in the et field.
  • \): Matches the closing parenthesis, escaped with a backslash to avoid Grok syntax conflicts.

Capture the Entire Log Line (Optional)

If you want to preserve the leading and trailing parts of the log line while extracting your target fields, use this expanded pattern:

%{GREEDYDATA:leading_text} Purging cache - END \(PID: %{NUMBER:pid:int}, QN: %{NUMBER:qn_current:int} / %{NUMBER:qn_total:int} , ET: %{NUMBER:et:int} \) %{GREEDYDATA:trailing_text}

This adds %{GREEDYDATA} fields for the text before and after your target segment, so you don't lose any context from the original log.

内容的提问来源于stack exchange,提问作者user486631

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:32:20