基于Perl的grep -m1 function实现日志匹配与时间对比需求
Solution Using Perl to Compare CASPER and YIGYO Transactions
Alright, let's break down how to implement your required logic with Perl. The core idea is to track state as we parse the log file, so we can pair each CASPER US_PARENT entry with its corresponding first YIGYO entry and compare their timestamps.
Key Logic Steps
- Track each unique
rootidthat has a CASPER US_PARENT entry, storing its timestamp and full line content - When we encounter the first YIGYO entry for a tracked
rootid, compare the two timestamps - If the CASPER timestamp is earlier than the YIGYO timestamp, output the full CASPER line
- Once a
rootidis processed, ignore any subsequent lines for it
Perl Script Implementation
#!/usr/bin/perl use strict; use warnings; # Hash to store unprocessed rootid data: key = rootid, value = { time => timestamp, line => full line } my %pending_rootids; while (my $line = <>) { chomp $line; # Handle CASPER US_PARENT lines if ($line =~ /CASPER US_PARENT/) { # Extract timestamp and rootid - ADJUST THESE REGEXES TO MATCH YOUR LOG FORMAT! # Example assumes timestamp is in ISO format (YYYY-MM-DD HH:MM:SS) and rootid is in "rootid=XYZ" format if ($line =~ /(\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2}).*rootid=(\S+)/) { my ($casper_ts, $rootid) = ($1, $2); # Only store if we haven't seen this rootid before $pending_rootids{$rootid} = { time => $casper_ts, line => $line } unless exists $pending_rootids{$rootid}; } next; } # Handle YIGYO lines if ($line =~ /apptype=YIGYO/) { # Extract rootid using the same pattern as above if ($line =~ /rootid=(\S+)/) { my $rootid = $1; # Check if we have a pending CASPER entry for this rootid if (my $casper_data = delete $pending_rootids{$rootid}) { # Extract YIGYO timestamp (match your log's timestamp format) if ($line =~ /(\d{4}-\d{2}-\d{2} \d{2}:\d{2}:\d{2})/) { my $yigyo_ts = $1; # ISO timestamps can be compared directly as strings if ($casper_data->{time} lt $yigyo_ts) { print "$casper_data->{line}\n"; } } } } next; } }
Important Notes
- Adjust Regex Patterns: The regexes for extracting timestamps and
rootidare examples. You'll need to modify them to match the actual structure of your log lines. For example, if your timestamp is in a different format orrootidis in a different position, update the capture groups accordingly. - Timestamp Comparison: Using ISO 8601 formatted timestamps (like
YYYY-MM-DD HH:MM:SS) allows us to compare them directly as strings withlt(less than) since their lexicographical order matches chronological order. If your timestamps use a different format, you may need to convert them to epoch time for accurate comparison. - Usage: Save the script as
casper_yigyo_compare.pl, make it executable (chmod +x casper_yigyo_compare.pl), then run it against your log file:./casper_yigyo_compare.pl your_log_file.log
内容的提问来源于stack exchange,提问作者capser
相关产品推荐
相关产品推荐

