Need help using awk script


 
Thread Tools Search this Thread
Top Forums Shell Programming and Scripting Need help using awk script
# 1  
Old 07-14-2016
Need help using awk script

Hi Gurus,

I have a log file as shown below:

Code:
2016-07-08T00:00:08-0700 10.10.10.1 63.128.163.28 - 500 1 5507 824 6047 69812 "https://www.plenti.com/" "GET /sign-up?step=char(39)&emid=0c3c23a9ccabed6feaaaf224a473eab8 HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:13.0) Gecko/20100101 Firefox/13.0.1 WhiteHat Security"
2016-07-08T00:00:08-0700 10.10.10.2 - - 200 0 2 54 281 3085 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:11-0700 10.10.10.1 63.128.163.28 - 500 0 5528 965 6068 59125 "https://www.plenti.com/" "GET /sign-up?step=%63%68%61%72%28%31%31%39%2C%31%30%34%2C%31%31%35%2C%31%30%30%2C%39%38%2C%31%31%36%2C%31%30%31%2C%31%31%35%2C%31%31%36%29&emid=0c3c23a9ccabed6feaaaf224a473eab8 HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:13.0) Gecko/20100101 Firefox/13.0.1 WhiteHat Security"
2016-07-08T00:00:12-0700 10.10.10.1 63.128.163.28 - 500 0 5533 923 6073 74076 "https://www.plenti.com/" "GET /sign-up?step=CHAR(119)%2bCHAR(104)%2bCHAR(115)%2bCHAR(83)%2bCHAR(81)%2bCHAR(76)%2bCHAR(105)&emid=0c3c23a9ccabed6feaaaf224a473eab8 HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:13.0) Gecko/20100101 Firefox/13.0.1 WhiteHat Security"
2016-07-08T00:00:13-0700 10.10.10.3 - - 200 0 2 54 281 3228 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:13-0700 10.10.10.2 - - 200 0 2 54 281 3047 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:13-0700 10.10.10.1 107.77.228.176 - 200 0 6551 663 7109 70544 "-" "GET /reset-password-pin HTTP/1.1" "Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13F69 Safari/601.1"
2016-07-08T00:00:13-0700 10.10.10.1 65.216.115.73 - 301 0 191 557 527 361 "-" "GET / HTTP/1.1" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko GomezAgent 3.0) Chrome/46.0.2490.71 Safari/537.36"
2016-07-08T00:00:15-0700 10.16.22.133 - - 200 0 984 215 1308 579 "-" "GET /server-status?auto HTTP/1.1" "metrics-sampler apache-status v0.7.3"
2016-07-08T00:00:15-0700 10.16.22.133 - - 200 0 351 145 669 8855 "-" "GET /apc_metrics.php HTTP/1.1" "metrics-sampler apache-status v0.7.3"
2016-07-08T00:00:18-0700 10.10.10.3 - - 200 0 2 54 281 3288 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:18-0700 10.10.10.2 - - 200 0 2 54 281 3756 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:20-0700 10.10.10.1 63.128.163.28 - 200 0 6151 852 6709 39024 "https://www.plenti.com/" "GET /sign-up?step=1'&emid=0c3c23a9ccabed6feaaaf224a473eab8 HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:13.0) Gecko/20100101 Firefox/13.0.1 WhiteHat Security"
2016-07-08T00:00:20-0700 10.10.10.1 63.128.163.28 - 500 0 5506 825 6046 49906 "https://www.plenti.com/" "GET /sign-up?step=%00'&emid=0c3c23a9ccabed6feaaaf224a473eab8 HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:13.0) Gecko/20100101 Firefox/13.0.1 WhiteHat Security"
2016-07-08T00:00:23-0700 10.10.10.3 - - 200 0 2 54 281 3122 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:23-0700 10.10.10.2 - - 200 0 2 54 281 2078 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:26-0700 10.10.10.1 163.246.121.40 - 200 0 56 2047 534 115703 "https://www.plenti.com/earn-points/partner-offers/partner-offer-details?page=details&id=11326" "POST /?:action=CouponsViewed HTTP/1.1" "Mozilla/5.0 (Windows NT 6.3; WOW64; Trident/7.0; rv:11.0) like Gecko"
2016-07-08T00:00:27-0700 10.10.10.3 - - 200 0 2 54 281 2833 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:28-0700 10.10.10.1 184.248.10.150 - 200 0 7484 615 8042 30280 "-" "GET / HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36"
2016-07-08T00:00:28-0700 10.10.10.2 - - 200 0 2 54 281 2922 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:29-0700 10.10.10.1 172.58.153.248 - 200 0 10964 3083 11696 451892 "-" "GET /earn-points/partner-offers HTTP/1.1" "Mozilla/5.0 (Linux; Android 5.1.1; Coolpad 3320A Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.81 Mobile Safari/537.36"
2016-07-08T00:00:32-0700 10.10.10.3 - - 200 0 2 54 281 3114 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:33-0700 10.10.10.2 - - 200 0 2 54 281 1997 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:33-0700 10.10.10.1 72.23.77.208 - 200 0 5965 546 6523 65317 "-" "GET /forgot-password HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; WOW64; rv:47.0) Gecko/20100101 Firefox/47.0"
2016-07-08T00:00:33-0700 10.10.10.1 63.128.163.28 - 500 0 5504 847 6044 69668 "https://www.plenti.com/" "GET /sign-up?step=\\\"&emid=0c3c23a9ccabed6feaaaf224a473eab8 HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:13.0) Gecko/20100101 Firefox/13.0.1 WhiteHat Security"
2016-07-08T00:00:35-0700 10.16.22.133 - - 200 0 984 215 1308 639 "-" "GET /server-status?auto HTTP/1.1" "metrics-sampler apache-status v0.7.3"
2016-07-08T00:00:35-0700 10.16.22.133 - - 200 0 351 145 669 9191 "-" "GET /apc_metrics.php HTTP/1.1" "metrics-sampler apache-status v0.7.3"
2016-07-08T00:00:37-0700 10.10.10.3 - - 200 0 2 54 281 2002 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:37-0700 10.10.10.1 172.58.153.248 - 200 0 5947 3489 6678 252373 "https://www.plenti.com/earn-points/partner-offers" "GET /earn-points/partner-offers/partner-offer-details?page=details&id=11172 HTTP/1.1" "Mozilla/5.0 (Linux; Android 5.1.1; Coolpad 3320A Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.81 Mobile Safari/537.36"
2016-07-08T00:00:38-0700 10.10.10.2 - - 200 0 2 54 281 3313 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:43-0700 10.10.10.3 - - 200 0 2 54 281 2252 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:43-0700 10.10.10.2 - - 200 0 2 54 281 3117 "-" "GET /status.html HTTP/1.1" "-"
2016-07-08T00:00:44-0700 10.10.10.1 98.206.13.213 - 200 0 7483 651 8041 39503 "-" "GET / HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.36"
2016-07-08T00:00:44-0700 10.10.10.1 63.128.163.28 - 500 0 5502 852 6042 53145 "https://www.plenti.com/" "GET /sign-up?step=%%32%37&emid=0c3c23a9ccabed6feaaaf224a473eab8 HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:13.0) Gecko/20100101 Firefox/13.0.1 WhiteHat Security"

in the above log file 5th filed (separated by space) is status code and I need to find how many status codes occurred on hourly basis.
I have extract date and hour
I have tried using the following but no luck, can some one help me?

Code:
awk -F [:\ ] '{print $1, $7}' ipcount.txt | awk '{s[$2]++; count[$1]++} END {for (var in s) print count[var], "access", s[var]," times"}'

I need output as following:

Code:
At 2016-07-13T15, 500 status code count is 1
At 2016-07-08T00, 500 status code count is 6

if you would split Date and time that would also great help to me,

Code:
At 2016-07-13, hour 15, 500 status code count is 1
At 2016-07-08, hour 00, 500 status code count is 6

Thank you So much for your help!!!
Vasu

---------- Post updated at 12:09 PM ---------- Previous update was at 11:50 AM ----------

Sorry, I am using the below script:

Code:
awk -F [:\ ] '{print $1, $7}' ipcount.txt | awk '{if($2="500") {s[$2]++; count[$1]+=$NF}} END {for (var in s) print count[var], "access", s[var]," times"}'

---------- Post updated at 12:22 PM ---------- Previous update was at 12:09 PM ----------

Code:
awk -F [:\ ] '{print $1, $7}' ipcount.txt | awk '{if($2="500") {s[$2]++; count[$1]++}} END {for (var in count) print "At", var, "access", s[var]," times"}'


Last edited by RudiC; 07-14-2016 at 04:25 PM.. Reason: Added code tags for last update.
# 2  
Old 07-14-2016
Would this come close to what you need?
Code:
awk -F [:\ ] '{sub (/T/, " ");  CNT[$1 OFS $2 OFS $8]++} END {for (c in CNT) print c, CNT[c]}' OFS="\t" file
2016-07-08	00	500	6
2016-07-08	00	301	1
2016-07-08	00	200	27

Formatting the output is left as an exercise for the reader.
This User Gave Thanks to RudiC For This Post:
# 3  
Old 07-14-2016
Thank you So much RudiC, I am getting this count from many servers and many files under each servers using the following script, but its not allowing me to get

Code:
for server in 01 02 03 04 12 13 14 15; do echo "--------$server--------Starting"; ssh web_pu@hvnplppuiw$server "for file in /apps/web/logs/httpd/portal/portal-www-access-2016-07-0[89].log; do echo "File Name: "$file; awk -F [:\ ] '{sub (/T/, " ");  if($8~500) CNT[$1":"$2]++} END {for (c in CNT) print c, "--", CNT[c]}' $file; echo "================================"; done" 2>&1 | grep -v 'THIS SYSTEM IS RESTRICTED'; echo "--------$server--------Ending"; done

I am getting following output Smilie

Code:
--------01--------Starting

File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
--------01--------Ending
--------02--------Starting

File Name:
================================
File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
--------02--------Ending
--------03--------Starting

File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
--------03--------Ending
--------04--------Starting

File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
--------04--------Ending
--------12--------Starting

File Name:
================================
File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
--------12--------Ending
--------13--------Starting

File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
--------13--------Ending
--------14--------Starting

File Name:
================================
File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
--------14--------Ending
--------15--------Starting

File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
File Name:
awk: {sub (/T/,  );  if(~500) CNT[:]++} END {for (c in CNT) print c, --, CNT[c]}
awk:             ^ syntax error
awk: fatal: 0 is invalid as number of arguments for sub
================================
--------15--------Ending

# 4  
Old 07-15-2016
Hello VasuKukkapalli,

I think(as per error I could say) you have used sub (/T/, ), could you please let us know if you used code as per Rudi's suggestion as sub (/T/, " "). When I tried(I am using BASH) this code it works fine for me.
Code:
awk -F [:\ ] '{sub (/T/, " ");  CNT[$1 OFS $2 OFS $8]++} END {for (c in CNT) print c, CNT[c]}' OFS="\t"   Input_file

Output is as follows.
Code:
2016-07-08      00      200     27
2016-07-08      00      301     1
2016-07-08      00      500     6

In case you didn't miss anything what RudiC has suggested then please do let us know which O.S you are using, code you are executing with complete errors please.

Thanks,
R. Singh
This User Gave Thanks to RavinderSingh13 For This Post:
# 5  
Old 07-15-2016
Looks like you messed up quoting. The command for ssh is double quoted, but some sequences inside are as well, annulling the former's effect. Try escaping those (inner) double quotes.

Why don't you assemble your script step by step, first check if the proposal does what you need by running it manually from the command line, then applying it in a script, then trying it within the ssh command alone, and maybe then only in a complex command sequence.
This User Gave Thanks to RudiC For This Post:
# 6  
Old 07-15-2016
Hello RavinderSingh, Thank you for your time, if take deeper look at the command, the double codes are present, the problem is i am sending this command to another host via ssh and executing there, in fact i need the execute one awk in many servers and get the output, that what i am doing here!!

---------- Post updated at 03:32 PM ---------- Previous update was at 03:29 PM ----------

Hello RudiC, Thank you for your time, I am executing one awk command on remote host using double quotes, but some how double quotes representing as ending to ssh command, i am not sure how to solve this. if you have any idea, would be great help, thank you!!
# 7  
Old 07-16-2016
I gave you two hints; did you try either?
This User Gave Thanks to RudiC For This Post:
Login or Register to Ask a Question

Previous Thread | Next Thread

10 More Discussions You Might Find Interesting

1. UNIX for Beginners Questions & Answers

Shell script to call and sort awk script and output

I'm trying to create a shell script that takes a awk script that I wrote and a filename as an argument. I was able to get that done but I'm having trouble figuring out how to keep the header of the output at the top but sort the rest of the rows alphabetically. This is what I have now but it is... (1 Reply)
Discussion started by: Eric7giants
1 Replies

2. Shell Programming and Scripting

awk script to call another script based on second column entry

Hi I have a text file (Input.txt) with two column entries separated by tab as given below: aaa str1 bbb str2 cccccc str3 dddd str4 eee str3 ssss str2 sdf str3 hhh str1 fff str2 ccc str3 ..... ..... ..... (1 Reply)
Discussion started by: my_Perl
1 Replies

3. UNIX for Dummies Questions & Answers

Passing shell script parameter value to awk command in side the script

I have a shell script (.sh) and I want to pass a parameter value to the awk command but I am getting exception, please assist. diff=$1$2.diff id=$2 new=new_$diff echo "My id is $1" echo "I want to sync for user account $id" ##awk command I am using is as below cat $diff |... (1 Reply)
Discussion started by: Sarita Behera
1 Replies

4. Post Here to Contact Site Administrators and Moderators

Unable to pass shell script parameter value to awk command in side the same script

Variable I have in my shell script diff=$1$2.diff id=$2 new=new_$diff echo "My id is $1" echo "I want to sync for user account $id" ##awk command I am using is as below cat $diff | awk -F'~' ''$2 == "$id"' {print $0}' > $new I could see value of $id is not passing to the awk... (0 Replies)
Discussion started by: Ashunayak
0 Replies

5. Shell Programming and Scripting

Calling shell script within awk script throws error

I am getting the following error while passing parameter to a shell script called within awk script. Any idea what's causing this issue and how to ix it ? Thanks sh: -c: line 0: syntax error near unexpected token `newline' sh: -c: line 0: `./billdatecalc.sh ... (10 Replies)
Discussion started by: Sudhakar333
10 Replies

6. Shell Programming and Scripting

Passing awk variable argument to a script which is being called inside awk

consider the script below sh /opt/hqe/hqapi1-client-5.0.0/bin/hqapi.sh alert list --host=localhost --port=7443 --user=hqadmin --password=hqadmin --secure=true >/tmp/alerts.xml awk -F'' '{for(i=1;i<=NF;i++){ if($i=="Alert id") { if(id!="") if(dt!=""){ cmd="sh someScript.sh... (2 Replies)
Discussion started by: vivek d r
2 Replies

7. Shell Programming and Scripting

Help: How to convert this bash+awk script in awk script only?

This is the final first release of the dynamic menu generator for pekwm (WM). #!/bin/bash function param_val { awk "/^${1}=/{gsub(/^${1}="'/,""); print; exit}' $2 } echo "Dynamic {" for CF in `ls -c1 /usr/share/applications/*.desktop` do name=$(param_val Name $CF) ... (3 Replies)
Discussion started by: alexscript
3 Replies

8. Shell Programming and Scripting

Call shell script function from awk script

hi everyone i am trying to do this bash> cat abc.sh deepak() { echo Deepak } deepak bash>./abc.sh Deepak so it is giving me write simply i created a func and it worked now i modified it like this way bash> cat abc.sh (2 Replies)
Discussion started by: aishsimplesweet
2 Replies

9. Shell Programming and Scripting

want to pass parameters to awk script from shell script

Hello, I have this awk script that I want to execute by passing parameters through a shell script. I'm a little confused. This awk script removes duplicates from an input file. Ok, so I have a .sh file called rem_dups.sh #!/usr/bin/sh... (4 Replies)
Discussion started by: script_op2a
4 Replies

10. Shell Programming and Scripting

create a shell script that calls another script and and an awk script

Hi guys I have a shell script that executes sql statemets and sends the output to a file.the script takes in parameters executes sql and sends the result to an output file. #!/bin/sh echo " $2 $3 $4 $5 $6 $7 isql -w400 -U$2 -S$5 -P$3 << xxx use $4 go print"**Changes to the table... (0 Replies)
Discussion started by: magikminox
0 Replies
Login or Register to Ask a Question