Events-log4j-parser: Difference between revisions

From NovaOrdis Knowledge Base
Jump to navigation Jump to search
Line 31: Line 31:
A query contains:
A query contains:
* keywords
* keywords
* event fields
* event properties
* regular expressions
* regular expressions


Line 55: Line 55:


are different.
are different.
Keywords are matched against each property.

Revision as of 01:15, 3 June 2017

Internal

Overview

A library that produces timed events from log4j logs.

GitHub

https://github.com/NovaOrdis/events-log4j-parser

Installation

Installs as a command line utility log4jp-<version>.zip.

TODO

./doc/Events log4j Parser TODO.docx.

Usage

log4jp <log-file> [query]

Query

The query filters the events that will displayed.

A query contains:

  • keywords
  • event properties
  • regular expressions

When multiple separate keywords are present in query, the query selects the union of events that contain each keyword.

blue red

will return all events that contain "blue" and all events that contain "red". Those events that contain both "blue" and "red" will be represented once in the returned set.

Note that

blue red

and

"blue red"

are different.

Keywords are matched against each property.