Re: Reporting on elements in the request line

Jeremy Wadsack <[email protected]> Tue, 10 Nov 2009 08:19:53 -0800
Newsgroups gmane.comp.web.analog.general
Message-ID <[email protected]>
--===============1020857155==
Content-Type: multipart/alternative; boundary=000e0cd5f2502741a8047806ae05

--000e0cd5f2502741a8047806ae05
Content-Type: text/plain; charset=ISO-8859-1

The Internal Search Word Report will give you a break down by phrases for
one or more base urls. See http://analog.cx/docs/args.html#SEARCHENGINE for
details on the command.

You can also use ARGSINCLUDE command (
http://analog.cx/docs/args.html#ARGSINCLUDE) if you just want to look at
certain arguments on a given URL. This breaks down the arguments for the URL
in the Request Report.

--
Jeremy Wadsack


On Tue, Nov 10, 2009 at 6:46 AM, Terry Chambers <[email protected]>wrote:

> Hi
>
> I've got log files from a Google Search appliance.  The data is located in
> the "request" value.
>
> 192.0.0.0 - - [05/Nov/2009:14:50:49 -0500] "GET
> /search?coutput=json&q=red+hat&btnG=Google+Search&access=p&client=default_frontend&sort=date%3AD%3AL%3Ad1&entqr=3&oe=UTF-8&ie=UTF-8&ud=1&site=default_collection&ip=192.0.0.0&num=100&filter=0&output=xml
> HTTP/1.1" 200 77014 438 0.12
>
> I'd like to be able to report off of the values such as "&client" and
> "&site" and "&q".
>
> Is there anyway to do that?
>
> For example, I'd love to be able to have a report that would show how many
> requests had "&site=default_collection" and then see the breakdown for any
> other values for &site=.
>
> Thanks
> Terry
>
> +------------------------------------------------------------------------
> |  TO UNSUBSCRIBE from this list:
> |    http://lists.meer.net/mailman/listinfo/analog-help
> |
> |  Analog Documentation: http://analog.cx/docs/Readme.html
> |  List archives:  http://www.analog.cx/docs/mailing.html#listarchives
> |  Usenet version: news://news.gmane.org/gmane.comp.web.analog.general
> +------------------------------------------------------------------------
>
>

--000e0cd5f2502741a8047806ae05
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

The Internal Search Word Report will give you a break down by phrases for o=
ne or more base urls. See <a href=3D"http://analog.cx/docs/args.html#SEARCH=
ENGINE">http://analog.cx/docs/args.html#SEARCHENGINE</a> for details on the=
 command.<br>
<br>You can also use ARGSINCLUDE command (<a href=3D"http://analog.cx/docs/=
args.html#ARGSINCLUDE">http://analog.cx/docs/args.html#ARGSINCLUDE</a>) if =
you just want to look at certain arguments on a given URL. This breaks down=
 the arguments for the URL in the Request Report.<br>
<br>--<br clear=3D"all">Jeremy Wadsack<br>
<br><br><div class=3D"gmail_quote">On Tue, Nov 10, 2009 at 6:46 AM, Terry C=
hambers <span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]">t=
[email protected]</a>&gt;</span> wrote:<br><blockquote class=3D"gmail=
_quote" style=3D"border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt=
 0pt 0.8ex; padding-left: 1ex;">
Hi<div><br></div><div>I&#39;ve got log files from a Google Search appliance=
. =A0The data is located in the &quot;request&quot; value.</div><div><br></=
div><div><span style=3D"font-family: arial,sans-serif; font-size: 13px; col=
or: rgb(34, 34, 34);">192.0.0.0 - - [05/Nov/2009:14:50:49 -0500] &quot;GET =
/search?coutput=3Djson&amp;q=3Dred+hat&amp;btnG=3DGoogle+Search&amp;access=
=3Dp&amp;client=3Ddefault_frontend&amp;sort=3Ddate%3AD%3AL%3Ad1&amp;entqr=
=3D3&amp;oe=3DUTF-8&amp;ie=3DUTF-8&amp;ud=3D1&amp;site=3Ddefault_collection=
&amp;ip=3D192.0.0.0&amp;num=3D100&amp;filter=3D0&amp;output=3Dxml HTTP/1.1&=
quot; 200 77014 438 0.12</span></div>


<div><br></div><div>I&#39;d like to be able to report off of the values suc=
h as &quot;&amp;client&quot; and &quot;&amp;site&quot; and &quot;&amp;q&quo=
t;.</div><div><br></div><div>Is there anyway to do that?</div><div><br>

</div><div>For example, I&#39;d love to be able to have a report that would=
 show how many requests had &quot;&amp;site=3Ddefault_collection&quot; and =
then see the breakdown for any other values for &amp;site=3D.</div><div><br=
>

</div><div>Thanks</div><div>Terry</div>
<br>+----------------------------------------------------------------------=
--<br>
| =A0TO UNSUBSCRIBE from this list:<br>
| =A0 =A0<a href=3D"http://lists.meer.net/mailman/listinfo/analog-help" tar=
get=3D"_blank">http://lists.meer.net/mailman/listinfo/analog-help</a><br>
|<br>
| =A0Analog Documentation: <a href=3D"http://analog.cx/docs/Readme.html" ta=
rget=3D"_blank">http://analog.cx/docs/Readme.html</a><br>
| =A0List archives: =A0<a href=3D"http://www.analog.cx/docs/mailing.html#li=
starchives" target=3D"_blank">http://www.analog.cx/docs/mailing.html#listar=
chives</a><br>
| =A0Usenet version: news://<a href=3D"http://news.gmane.org/gmane.comp.web=
.analog.general" target=3D"_blank">news.gmane.org/gmane.comp.web.analog.gen=
eral</a><br>
+------------------------------------------------------------------------<b=
r>
<br></blockquote></div><br>

--000e0cd5f2502741a8047806ae05--

--===============1020857155==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

+------------------------------------------------------------------------
|  TO UNSUBSCRIBE from this list:
|    http://lists.meer.net/mailman/listinfo/analog-help
|
|  Analog Documentation: http://analog.cx/docs/Readme.html
|  List archives:  http://www.analog.cx/docs/mailing.html#listarchives
|  Usenet version: news://news.gmane.org/gmane.comp.web.analog.general
+------------------------------------------------------------------------

--===============1020857155==--