grep1-7 Exercise 1: Slowest Requests and Rotated Logs ====================================================== (Run in a fresh copy of the practice data from the chapter. Make it first with the block at the top of the chapter.) echo "three slowest requests (id, method, path, status, time):" grep -oP 'req=\K\S+ [A-Z]+ /\S+ [0-9]+ took=[0-9]+' service.log | sort -t= -k2 -rn | head -3 echo echo "errors in the current and the rotated log together:" zgrep -h ERROR service.log service.log.1.gz | wc -l echo echo "failed requests (status 500 or over) in the rotated log:" zgrep -cE ' (5[0-9]{2}) took=' service.log.1.gz Output: three slowest requests (id, method, path, status, time): f6a8 POST /checkout 500 took=3050 f6a8 POST /checkout 500 took=2210 d0e2 GET /search 200 took=1800 errors in the current and the rotated log together: 7 failed requests (status 500 or over) in the rotated log: 1 WHY THIS WORKS AS AN ANSWER --------------------------- -oP with \K starts the output right after 'req=' and takes the id, method, path, status and the 'took=NNN' part, one request per line. Because \K threw away the 'req=' part, the only '=' left on each line is the one in 'took=NNN'. So sort -t= splits at it, -k2 is the number after it, -n sorts numerically and -r puts the biggest first; head -3 keeps three. (If the line still contained other '=' characters, the field numbers would be different, which is why the order of these steps matters.) The two slowest are the same request, f6a8, failing twice in a row. zgrep -h searches the compressed file as well as the plain one without unpacking it, and -h keeps the output free of file names so wc -l can count lines. zgrep -cE counts the rotated log's lines with a status of 500 or over: the pattern looks for ' 5NN took=', which is how a failed request is written in this log.