Count and rank matches
Count and rank matches
Group the matches of a pattern by a key rendered at each, rank the keys, and total a typed value per key. The keys and aggregates are on aggregates.
$ cat access.log
10.0.0.5 GET /index.html 200 5120
10.0.0.7 GET /login 302 0
10.0.1.9 GET /missing 404 312
10.0.0.5 POST /login 200 88
$ cat sizes.txt
alpha 1000B 80ms
alpha 2000B 80ms
alpha 4000B 80ms
beta 8000B 300ms
Rank the most frequent
The key is a template: here the verb each request bound. top puts the most frequent first,
count-by orders by key:
$ trex top '\I:ip \W:verb' '${verb}' access.log
GET 3
POST 1
Count by part of a value
A typed slice in the key groups by part of what a register bound, here the first three octets of each address:
$ trex count-by '\I:ip' '${ip:octet1-3}' access.log
10.0.0 3
10.0.1 1
Total a value per key
--sum adds a column over one register’s typed value, in its base unit: bytes for a size.
--avg, --min, --max, --p50 and --p95 work the same way.
$ trex count-by '\W:h \Z:s' '${h}' sizes.txt --sum '${s}' --min '${s}' --max '${s}'
count --sum s --min s --max s
alpha 3 7000 1000 4000
beta 1 8000 8000 8000
Every key is printed; -n N keeps the first N rows and says how many there were.