11-04-2009
Thank you all for the reply...
Daptal your program does exatctly what I want..exept i get error Date::Calc:
elta_YMDHMS(): not a valid date when I use a day gerater then 11. for example 11/15/2009 07:53:38 will not calculate the difference...
Below the actual log file data, i am still trying to modify the reg expression to capture the phrasees within a long lines of various characters and numbers.
The algorithm for the script for log file from a machine:
1. Find when the first time TV error occures end of the line with unique phrase ="MMeas"'
2. The TV error will stop the machine and multiple error might occure afterwards, the script should skip these errors.
3. Find when the machine start back up (W_NO) and within the long line there is this unique phrase name="WWWW_NO" and the value="A333BBBB.rf"
4. the output of the script should show (calculate) when the first TV error happens and when the machine start back up. These events could happen through out the day.
5. Calculate the total time differences of all the events (of waiting between the first error and next machine start).
Best Regards,,,
bataf
Last edited by bataf; 11-05-2009 at 02:35 AM..
10 More Discussions You Might Find Interesting
1. Shell Programming and Scripting
Hi All,
I have a file that I need to be able to find a pattern match on a line, search that line for a text pattern, and replace that text.
An example of 4 lines in my file is:
1. MatchText_randomNumberOfText moreData ReplaceMe moreData
2. MatchText_randomNumberOfText moreData moreData... (4 Replies)
Discussion started by: Crypto
4 Replies
2. Shell Programming and Scripting
Hi Everyone,
i have a string 00:44:40
so:
$tmp=~ s/://gi;
$tmp=~s/({2})({2})({2})/$1*3600+$2*60+$3/e;
the output is 2680.
Any way to combine this two lines into a single line?
Thanks (4 Replies)
Discussion started by: jimmy_y
4 Replies
3. Shell Programming and Scripting
Hi Experts,
i am beginner in perl and need your help to find a solution.. I have a block of multiple lines like below say module 1 to module 100
***** MAKING > module1 **************
kvmfkvmmfdv
svksmnvlksmfvks dcsdvcs
sddvcsv ssvsdvdf error: abcdefghi
wrw wvsv dsvds sdvsd
error:... (5 Replies)
Discussion started by: ganga.dharan
5 Replies
4. Shell Programming and Scripting
Hi,
my xml files looks something like this
<Instance Name="New York">
<Description></Description>
<Instance Name="A">
<Description></Description>
<PropertyValue Key="false" Name="Building A" />
</Instance>
<Instance Name="B">
... (4 Replies)
Discussion started by: tententen
4 Replies
5. Shell Programming and Scripting
Dear All,
i want to search particular string and want to replance next line value.
following is the test file.
search string is
tmp,???
,10:1 "???" may contain any 3 character it should remain the same and next line replace with ,10:50
tmp,123 --- if match tmp,??? then... (3 Replies)
Discussion started by: arvindng
3 Replies
6. Shell Programming and Scripting
hey guys,
I tried searching but most 'search and replace' questions are related to one liners.
Say I have a file to be replaced that has the following:
$ cat testing.txt
TESTING
AAA
BBB
CCC
DDD
EEE
FFF
GGG
HHH
ENDTESTING
This is the input file: (3 Replies)
Discussion started by: DeuceLee
3 Replies
7. Shell Programming and Scripting
Hi all,
I have a vcd file with a bunch of lines containing an array, like this
$var wire 1 b a $end
$var wire 1 c a $end
$var wire 1 d a $end
$var wire 1 e a $end
$var wire 1 f b $end
$var wire 1 g b $end
$var wire 1 h b $end
$var wire 1 i b $end
I want it like this:
$var wire 1 e a... (12 Replies)
Discussion started by: veerabahu
12 Replies
8. Shell Programming and Scripting
Hi ,
I have been trying to write a perl script to do this job. But i am not able to achieve the desired result. Below is my code.
my $current_value=12345;
my @users=("bob","ben","tom","harry");
open DBLIST,"<","/var/tmp/DBinfo";
my @input = <DBLIST>;
foreach (@users)
{
my... (11 Replies)
Discussion started by: chidori
11 Replies
9. Shell Programming and Scripting
#Build label and text box
$main->Label(
-text => "Input string below:"
)->pack();
$main->Entry(
-textvariable => \$text456
)->pack();
$main->Button(
-text => "Search",
-command =>
sub {
errchk ($text456)
... (4 Replies)
Discussion started by: popeye
4 Replies
10. Shell Programming and Scripting
Hi,
I've written a script to search for an Oracle ORA- error on a log file, print that line and the .trc file associated with it as well as the dateline of when I assumed the error occured. In most it is the first dateline previous to the error.
Unfortunately, this is not a fool proof script.... (2 Replies)
Discussion started by: newbie_01
2 Replies
LEARN ABOUT SUSE
aureport
AUREPORT:(8) System Administration Utilities AUREPORT:(8)
NAME
aureport - a tool that produces summary reports of audit daemon logs
SYNOPSIS
aureport [options]
DESCRIPTION
aureport is a tool that produces summary reports of the audit system logs. The aureport utility can also take input from stdin as long as
the input is the raw log data. The reports have a column label at the top to help with interpretation of the various fields. Except for the
main summary report, all reports have the audit event number. You can subsequently lookup the full event with ausearch -a event number. You
may need to specify start & stop times if you get multiple hits. The reports produced by aureport can be used as building blocks for more
complicated analysis.
OPTIONS
-au, --auth
Report about authentication attempts
-a, --avc
Report about avc messages
-c, --config
Report about config changes
-cr, --crypto
Report about crypto events
-e, --event
Report about events
-f, --file
Report about files
--failed
Only select failed events for processing in the reports. The default is both success and failed events.
-h, --host
Report about hosts
-i, --interpret
Interpret numeric entities into text. For example, uid is converted to account name. The conversion is done using the current
resources of the machine where the search is being run. If you have renamed the accounts, or don't have the same accounts on
your machine, you could get misleading results.
-if, --input file
Use the given file instead if the logs. This is to aid analysis where the logs have been moved to another machine or only part of a
log was saved.
--input-logs
Use the log file location from auditd.conf as input for analysis. This is needed if you are using aureport from a cron job.
-k, --key
Report about audit rule keys
-l, --login
Report about logins
-m, --mods
Report about account modifications
-ma, --mac
Report about Mandatory Access Control (MAC) events
--node node-name
Only select events originating from node name string for processing in the reports. The default is to include all nodes. Multiple
nodes are allowed.
-p, --pid
Report about processes
-r, --response
Report about responses to anomaly events
-s, --syscall
Report about syscalls
--success
Only select successful events for processing in the reports. The default is both success and failed events.
--summary
Run the summary report that gives a total of the elements of the main report. Not all reports have a summary.
-t, --log
This option will output a report of the start and end times for each log.
--tty Report about tty keystrokes
-te, --end [end-date] [end-time]
Search for events with time stamps equal to or before the given end time. The format of end time depends on your locale. If the date
is omitted, today is assumed. If the time is omitted, now is assumed. Use 24 hour clock time rather than AM or PM to specify time.
An example date using the en_US.utf8 locale is 09/03/2009. An example of time is 18:00:00. The date format accepted is influenced by
the LC_TIME environmental variable.
You may also use the word: now, recent, today, yesterday, this-week, week-ago, this-month, this-year. Today means starting now.
Recent is 10 minutes ago. Yesterday is 1 second after midnight the previous day. This-week means starting 1 second after midnight on
day 0 of the week determined by your locale (see localtime). This-month means 1 second after midnight on day 1 of the month.
This-year means the 1 second after midnight on the first day of the first month.
-tm, --terminal
Report about terminals
-ts, --start [start-date] [start-time]
Search for events with time stamps equal to or after the given end time. The format of end time depends on your locale. If the date
is omitted, today is assumed. If the time is omitted, midnight is assumed. Use 24 hour clock time rather than AM or PM to specify
time. An example date using the en_US.utf8 locale is 09/03/2009. An example of time is 18:00:00. The date format accepted is influ-
enced by the LC_TIME environmental variable.
You may also use the word: now, recent, today, yesterday, this-week, this-month, this-year. Today means starting at 1 second after
midnight. Recent is 10 minutes ago. Yesterday is 1 second after midnight the previous day. This-week means starting 1 second after
midnight on day 0 of the week determined by your locale (see localtime). This-month means 1 second after midnight on day 1 of the
month. This-year means the 1 second after midnight on the first day of the first month.
-u, --user
Report about users
-v, --version
Print the version and exit
-x, --executable
Report about executables
SEE ALSO
ausearch(8), auditd(8).
Red Hat Sept 2009 AUREPORT:(8)