nginx access.log如下格式:
192.168.2.112 - - [24/Feb/2017:23:15:13 +0800] "GET /favicon.ico HTTP/1.1" 200 21630 "http://192.168.2.99/interface/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-"
192.168.2.112 - - [24/Feb/2017:23:15:14 +0800] "GET /interface/ HTTP/1.1" 304 0 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-"
192.168.2.112 - - [24/Feb/2017:23:15:14 +0800] "GET /favicon.ico HTTP/1.1" 200 21630 "http://192.168.2.99/interface/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-"
192.168.2.112 - - [24/Feb/2017:23:15:14 +0800] "GET /interface/ HTTP/1.1" 200 159 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-"
192.168.2.112 - - [24/Feb/2017:23:15:14 +0800] "GET /favicon.ico HTTP/1.1" 200 21630 "http://192.168.2.99/interface/" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.99 Safari/537.36" "-"
192.168.2.120 - - [25/Feb/2017:16:57:41 +0800] "GET /favicon.ico HTTP/1.1" 200 21630 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36" "-"
awk命令:
awk -F '[\] "\[]' '{print $1"\t"$2"\t"$3"\t"$4"\t"$5"\t"$6"\t"$7}' logs/host.access.log > linshi3.log
-F后面表示多种分割符 如上表示用],空格,双引号,[ 进行数据分割,】和【 用反斜线转义。$1,$2 表示分割后的单元 。"\t" 表示制表,控制回显的格式,便于查看。
linshi3.log内容如下:
192.168.2.120 - - 24/Feb/2017:19:52:46 +0800
192.168.2.120 - - 24/Feb/2017:19:52:46 +0800
192.168.2.120 - - 24/Feb/2017:19:52:46 +0800
192.168.2.120 - - 24/Feb/2017:19:52:46 +0800
192.168.2.120 - - 24/Feb/2017:19:52:46 +0800
192.168.2.120 - - 24/Feb/2017:19:52:46 +0800