Skip to content
Count and rank matches

Count and rank matches

Count and rank matches

Group the matches of a pattern by a key rendered at each, rank the keys, and total a typed value per key. The keys and aggregates are on aggregates.

$ cat access.log
10.0.0.5 GET /index.html 200 5120
10.0.0.7 GET /login 302 0
10.0.1.9 GET /missing 404 312
10.0.0.5 POST /login 200 88
$ cat sizes.txt
alpha 1000B 80ms
alpha 2000B 80ms
alpha 4000B 80ms
beta 8000B 300ms

Rank the most frequent

The key is a template: here the verb each request bound. top puts the most frequent first, count-by orders by key:

$ trex top '\I:ip \W:verb' '${verb}' access.log
GET   3
POST  1

Count by part of a value

A typed slice in the key groups by part of what a register bound, here the first three octets of each address:

$ trex count-by '\I:ip' '${ip:octet1-3}' access.log
10.0.0  3
10.0.1  1

Total a value per key

--sum adds a column over one register’s typed value, in its base unit: bytes for a size. --avg, --min, --max, --p50 and --p95 work the same way.

$ trex count-by '\W:h \Z:s' '${h}' sizes.txt --sum '${s}' --min '${s}' --max '${s}'
       count  --sum s  --min s  --max s
alpha      3     7000     1000     4000
beta       1     8000     8000     8000

Every key is printed; -n N keeps the first N rows and says how many there were.