LogParser CASE语句含BETWEEN时语法报错,请求修正指导
Let's break down what's going wrong and fix your query step by step.
The Root Cause
Your original nested CASE syntax doesn't align with LogParser's rules. When you start with a simple CASE <expression> WHEN <value> structure, you can't re-specify the Last_update expression in nested CASE blocks the way you did—this is why you're getting the "expecting WHEN keyword" error.
Plus, your original query was returning numeric values (like 0, 999) instead of the string group names you actually need ('Day', 'Never', etc.), which doesn't match your requirements.
Corrected LogParser Query
We'll use a searched CASE statement (where we define explicit conditions with WHEN for each scenario) — this is far cleaner for mixed exact-value and range-based checks, and it's fully compatible with LogParser:
logparser "SELECT CASE WHEN Last_update = '0' THEN 'Day' WHEN Last_update BETWEEN '1' AND '31' THEN 'Within Month' WHEN Last_update = '999' THEN 'Never' ELSE 'Later last month' END AS Last_connection, SUM(nbhardware) AS sum_devices INTO 'output.csv' FROM 'report.csv' GROUP BY Last_connection ORDER BY sum_devices DESC"
Key Changes Explained
- Removed nested
CASEblocks: The searchedCASEstructure lets us list all conditions in a single, linear block, avoiding syntax conflicts. - Matched your grouping requirements: Each condition now returns the exact string label you specified (
'Day','Within Month', etc.) instead of numeric placeholders. - Preserved all logic: We kept every rule from your original requirement:
Last_update = '0'→'Day'1 ≤ Last_update ≤ 31→'Within Month'Last_update = '999'→'Never'- All other values →
'Later last month'
This query should run without syntax errors and produce the grouped device counts you need in output.csv.
内容的提问来源于stack exchange,提问作者ThomasP

