Skip to content
Find rare lines and out-of-order times

Find rare lines and out-of-order times

Find rare lines and out-of-order times

Find the lines whose shape a log seldom repeats, and the timestamps that run backward (axis predicates and anchors).

$ cat times.log
2026-09-15T10:00:00Z GET /a 200
2026-09-15T10:01:00Z GET /b 200
2026-09-15T09:58:00Z GET /c 200
2026-09-15T10:02:00Z GET /d 200
kernel: disk failure on /dev/sda

A timestamp earlier than the one before it

@order:desc holds on a timestamp before the timestamp token ahead of it in the stream:

$ trex scan '@order:desc \T' times.log
[64..84] "2026-09-15T09:58:00Z"

A line of a rare shape

@shape:rare holds at every token of a line whose template covers fewer lines than the mean template does; @shape:rare<5 fewer than five, @shape:rare<1% less than one percent of the lines:

$ trex scan '@shape:rare \W' times.log
[128..134] "kernel"
[136..140] "disk"
[141..148] "failure"
[149..151] "on"

trex templates --rare lists the rare templates themselves (summarize a log by templates).