【发布时间】:2016-03-21 14:39:15
【问题描述】:
我在分析 nginx 日志方面需要帮助。日志样本:
10.10.10.10 - - [21/Mar/2016:00:00:00 +0000] "GET /example?page=&per_page=100&scopes= HTTP/1.1" 200 769 "-" "" "1.1.1.1"
10.10.10.10 - - [21/Mar/2016:00:00:00 +0000] "GET /example?page=&per_page=500&scopes= HTTP/1.1" 200 769 "-" "" "1.1.1.1"
11.11.11.11 - - [21/Mar/2016:00:00:00 +0000] "GET /example?page=&per_page=10&scopes= HTTP/1.1" 200 769 "-" "" "1.1.1.1"
12.12.12.12 - - [21/Mar/2016:00:00:00 +0000] "GET /example?page=&per_page=500&scopes= HTTP/1.1" 200 769 "-" "" "1.1.1.1"
13.13.13.13 - - [21/Mar/2016:00:00:00 +0000] "GET /example HTTP/1.1" 200 769 "-" "" "1.1.1.1"
是否可以用 count 选择所有包含 per_page 参数且该参数等于或大于 100 的 uniq ip 地址?
所以,输出可以是任何格式:
10.10.10.10 - 2 # ip 10.10.10.10 was found twice
12.12.12.12 - 1
一个命令就可以搞定吗?
【问题讨论】: