Tomcat访问日志分析请求:解析日志格式与日志内容
First, let's break down each component of your Tomcat access log pattern:pattern="%h %H %l %u %t "%r" %s %b location: %{location}o"
(Note: " is just an HTML entity for double quotes, so the actual log format string translates to %h %H %l %u %t "%r" %s %b location: %{location}o)
Here's what each placeholder means:
%h: Remote host (the IP address of the client sending the request)%H: The HTTP protocol version used for the request (e.g., HTTP/1.1, HTTP/2)%l: Remote logical username from identd service — this is almost always-because identd is rarely enabled or used today%u: Remote user authenticated via HTTP Basic/Digest auth —-indicates no authenticated user was present%t: Timestamp of the request, formatted as[dd/MMM/yyyy:HH:mm:ss zzz](includes timezone offset)"%r": Full request line from the client, wrapped in quotes — includes the HTTP method, request URI, and protocol%s: HTTP status code returned to the client (e.g., 200 for success, 500 for server error)%b: Size of the response body in bytes (excluding headers) —-means either zero bytes or no response body was sentlocation: %{location}o: The value of theLocationresponse header sent by the server —-means this header wasn't included in the response
Analysis of Your Provided Log Entries
Let's walk through the complete log lines you shared:
First Log Entry:
10.103.62.207 HTTP/1.1 - - [03/Apr/2018:11:46:02 -0400] "GET / HTTP/1.1" 200 1150 location: -
- Client: Request came from IP
10.103.62.207using HTTP/1.1 - Auth/Ident: No authenticated user, and identd info isn't available (both
-) - Timestamp: Request was made on April 3, 2018 at 11:46:02 AM (UTC-4 timezone)
- Request: Client sent a
GETrequest to the root URI (/) - Response: Server returned a
200 OKstatus (successful request) with a 1150-byte response body (likely the homepage content) - Location Header: No redirect was sent (hence
-), which makes sense for a successful root page load
Second Log Entry:
10.103.62.207 HTTP/1.1 - - [03/Apr/2018:11:46:03 -0400] "GET /prweb/PRServletLDAP2 HTTP/1.1" 500 2375 location: -
- Client: Same IP as the first request, so it's the same client making a follow-up request one second later
- Request: Client tried to access
/prweb/PRServletLDAP2— this looks like a LDAP authentication servlet commonly used in Pega Platform applications - Response: Server returned a
500 Internal Server Error— this indicates an unexpected issue on the server side (e.g., code exception, LDAP connection failure, missing configuration) - Response Body: The 2375-byte body is almost certainly an error page or stack trace that provides more details about the failure
- Location Header: No redirect sent (standard for 500 errors, since the server can't fulfill the request to redirect)
The truncated entry (10.103.62.207 HTT...) suggests another request from the same client, but we can't analyze it fully without the complete line.
内容的提问来源于stack exchange,提问作者Pradeep Pydi

