python 日志增量抓取实现

import time
import pickle
import os
import re

class LogIncScaner(object):
    def __init__(self,log_file, reg_ex,seek_file='/tmp/log-inc-scan.seek.temp'):
        self.log_file = log_file
        self.reg_ex = reg_ex
        self.seek_file = seek_file

    def scan(self):
        seek = self._get_seek()
        file_mtime = os.path.getmtime(self.log_file)
        if file_mtime <= seek['time']:
            print 'file mtime not change since last scan'
            seek['time'] = file_mtime
            self._dump_seek(seek)
            return []

        file_size = os.path.getsize(self.log_file)
        if file_size <= seek['position']:
            print 'file size not change since last scan'
            seek['position'] = file_size
            self._dump_seek(seek)
            return []

        print 'file changed,start to scan'
        matchs = []
        with open(self.log_file, 'rb') as logfd:
            logfd.seek(seek['position'],os.SEEK_SET)
            for match in re.finditer(self.reg_ex, logfd.read()):
                matchs.append(match)
            seek = {'time':time.time(),'position': logfd.tell()}
            print seek
            self._dump_seek(seek)
        return matchs

    def _get_seek(self):
        seek = {'time':time.time(),'position':0}
        if os.path.exists(self.seek_file):
            with open(self.seek_file,'rb') as seekfd:
                    try:
                        seek = pickle.load(seekfd)
                    except:
                        pass
        print seek
        return seek

    def _dump_seek(self, seek):
        with open(self.seek_file,'wb') as seekfd:
            pickle.dump(seek,seekfd)

    def reset_seek(self):
        self._dump_seek({'time':time.time(),'position':0})

if __name__ == "__main__":
    scaner = LogIncScaner('/var/log/messages',r'(\w+ \d+ \d+:\d+:\d+) .+?exception')
    scaner.reset_seek()
    while True:
        matchs = scaner.scan()
        for match in matchs:
            print 'fond at:' + match.group(1) + ' content:' + match.group(0)
        time.sleep(5)

  • 3
    点赞
  • 9
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值