Find rare lines and out-of-order times
Find rare lines and out-of-order times
Find the lines whose shape a log seldom repeats, and the timestamps that run backward (axis predicates and anchors).
$ cat times.log
2026-09-15T10:00:00Z GET /a 200
2026-09-15T10:01:00Z GET /b 200
2026-09-15T09:58:00Z GET /c 200
2026-09-15T10:02:00Z GET /d 200
kernel: disk failure on /dev/sda
A timestamp earlier than the one before it
@order:desc holds on a timestamp before the timestamp token ahead of it in the stream:
$ trex scan '@order:desc \T' times.log
[64..84] "2026-09-15T09:58:00Z"
A line of a rare shape
@shape:rare holds at every token of a line whose template covers fewer lines than the mean
template does; @shape:rare<5 fewer than five, @shape:rare<1% less than one percent of the
lines:
$ trex scan '@shape:rare \W' times.log
[128..134] "kernel"
[136..140] "disk"
[141..148] "failure"
[149..151] "on"
trex templates --rare lists the rare templates themselves (summarize a log by
templates).