Log Parser分析IIS log的举例

本文介绍如何使用LogParser工具分析IIS日志文件,包括筛选特定日志条目、排序时间消耗等操作,并提供了实例代码及解析结果。

命令举例如下:

C:\Program Files (x86)\Log Parser 2.2>logparser.exe -i:IISW3C "select time-taken as Duration from 'D:\IIS Log Folder\ex100817_6371.log' order by time-taken desc"

 

结果返回:

Duration
--------
190971
154861
154861
145783
124642
124642
101876
99907
80547
77563
Press a key...

 

image

 

Example Snip

=============

#Software: Microsoft Internet Information Services 7.5
#Version: 1.0
#Date: 2011-10-04 06:28:57
#Fields: date time s-ip cs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent) sc-status sc-substatus sc-win32-status time-taken
2011-10-04 06:28:57 fe80::1587:9a8b:df87:50a%17 GET /_layouts/viewlsts.aspx BaseType=0 80 - fe80::1587:9a8b:df87:50a%17 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.1;+WOW64;+Trident/4.0;+SLCC2;+.NET+CLR+2.0.50727;+.NET+CLR+3.5.30729;+.NET+CLR+3.0.30729;+InfoPath.3;+MS-RTC+LM+8;+.NET4.0C;+.NET4.0E) 401 1 2148074254 26707
2011-10-04 06:29:09 fe80::1587:9a8b:df87:50a%17 GET /_layouts/viewlsts.aspx BaseType=0 80 - fe80::1587:9a8b:df87:50a%17 Mozilla/4.0+(compatible;+MSIE+7.0;+Windows+NT+6.1;+WOW64;+Trident/4.0;+SLCC2;+.NET+CLR+2.0.50727;+.NET+CLR+3.5.30729;+.NET+CLR+3.0.30729;+InfoPath.3;+MS-RTC+LM+8;+.NET4.0C;+.NET4.0E) 401 1 2148074254 15

 

Formatted Version

============

DateTimeServer IP AddressMethodURI StemURI QueryServer Port User NameClient IP AddressUser AgentHTTP StatusProtocol SubstatusWin32 StatusTime Taken
date time s-ipcs-method cs-uri-stem cs-uri-query s-port cs-username c-ip cs(User-Agent)sc-status sc-substatus sc-win32-status time-taken
2011-10-0406:28:57fe80::1587:9a8b:df87:50a%17GET/_layouts/viewlsts.aspx BaseType=080-fe80::1587:9a8b:df87:50a%17Mozilla/4.0+(compatible;+MSIE+7.0;
+Windows+NT+6.1;
+WOW64;+Trident/4.0;
+SLCC2;+.NET+CLR+2.0.50727;
+.NET+CLR+3.5.30729;
+.NET+CLR+3.0.30729;
+InfoPath.3;+MS
-
RTC+LM+8;+.NET4.0C;+.NET4.0E)
401 12148074254 26707

 

2011-10-07 举例更新

c:\Program Files (x86)\Log Parser 2.2>logparser.exe -i:IISW3C "select time-taken, cs-uri-stem, date, time, s-ip  from 'c:\temp\u_ex111005-2.log' where cs-uri-stem like'%.aspx' order by time-taken desc"

 

参考资料:

http://www.msexchange.org/tutorials/Using-Logparser-Utility-Analyze-ExchangeIIS-Logs.html

W3C Extended Log File Format (IIS 6.0)

http://www.microsoft.com/technet/prodtechnol/WindowsServer2003/Library/IIS/676400bc-8969-4aa7-851a-9319490a9bbb.mspx?mfr=true

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值