Re: New project: Log-parser
| From: | Matthew Palmer | Date: | Sat, 10 May 2003 07:13:54 +0000 |
| Subject: | Re: New project: Log-parser | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-16093@lists.php.net to get a copy of this message | ||
On Sat, 10 May 2003, Tobias Schlitt wrote:
> So, if anyone has to much spare-time in the next few weeks and
> is interessted in parsing different application-logs, please
> feel invited to join this project!
Just thinking quickly about it, I'd say the way to go would be to have a
specific class for each type of log, inheriting from a generic "log entry"
class. Reading a log file would involve giving the filename and the type of
log entries you're expecting, and getting back an array of log entries.
Each log entry class would, of course, have it's own elements, with
individual names. An apache entry, for instance, might have timestamp,
source, referrer, URL, user, result code, size, etc. Syslog would be pretty
straightforward - time and message (perhaps process and PID, for most
messages).
To get to the different bits of the log entry, you'd either have one
accessor (Element(), for instance) which you gave the name of the element
you wanted to get, or perhaps accessors named for each element. Each class
would have a Parse() method which took a string and broke it up into it's
bits for retrieval by Element().
So, for instance, to read your apache access log and count the total number
of bytes served, you might do something like:
$entries = Log_Parser::Read('/var/log/apache/access.log', 'apache_access');
foreach ($entries as $e)
{
$total += $e->Element('size');
}
And to count the number of times each URL was accessed:
$entries = Log_Parser::Read('/var/log/apache/access.log', 'apache_access');
foreach ($entries as $e)
{
$totals[$e->Element('URL')]++;
}
foreach ($totals as $URL => $count)
{
echo "$URL was accessed $count times\n";
}
You may have thought of all this - if so, I guess it must be a good idea if
two of us thought of it. All of the above has come off the top of my head,
thinking about the issue at hand.
--
-----------------------------------------------------------------------
#include <disclaimer.h>
Matthew Palmer, Geek In Residence
http://ieee.uow.edu.au/~mjp16