《日志格式规范》由会员分享,可在线阅读,更多相关《日志格式规范(4页珍藏版)》请在金锄头文库上搜索。
1、-日志格式标准日志文件的格式设定需要根据不同的效劳器来设置:APACHE 或 Tomcat 效劳器Apache 和 Tomcat 等采用默认格式即可IIS 效劳器1. 在“属性窗口, “标签中在“启用日志记录前打勾,并在“活动日志格式中选择“W3C 扩展日志文件格式。2.点击“活动日志格式右侧的“属性,设置“常规属性。在“新建日志时间选项选择“每天,在“文件命名和回卷使用当地时间前打勾。系统日志默认存放位置是“C:WINDOWSsystem32LogFiles,建议设置到一个容量大的非系统盘。3 点击“活动日志格式右侧的“属性,设置“扩展属性。在“扩展日志记录选项里选择如下选项,并点击“确定保
2、存。(1) 日期date(2) 时间time(3) 客户端 IP 地址c-ip(4) 用户名cs-username(5) 方法cs-method(6) URI 资源cs-uri-stem(7) URI 查询cs-uri-query(8) 协议状态sc-status(9) 发送的字节数sc-bytes(10) 协议版本cs-version(11) 用户代理csUser-Agent)(12) 引用站点csReferer)日志格式的定义请参考下面列表:日志记录如下所示 (NCSA bined/*LF/ELF log format):62.161.78.73 dd/mmm/yyyy:hh:mm:ss
3、+0*00 GET /page.html/1.1 200 1234 .from./from.htmMozilla/4.0 (patible; MSIE 5.01; Windows NT 5.0)格式定义: LogFormat=1也可使用:LogFormat=%host %other %logname %time1 %methodurl %code %bytesd %refererquot %uaqu ot日志记录如下所示 (NCSA bined with several virtualhostname sharing same log file).virtualserver1 62.161.7
4、8.73 - - dd/mmm/yyyy:hh:mm:ss +0*00 GET /page.html/1.1 200 1234.from./from.htm Mozilla/4.0 (patible; MSIE 5.01; Windows NT 5.0).z.-格式定义 :LogFormat=%virtualname %host %other %logname %time1 %methodurl %code %bytesd %refer erquot %uaquot日志记录如下所示 (NCSA bined and mod_gzip format 1 with Apache 1.*):62.16
5、1.78.73 - - dd/mmm/yyyy:hh:mm:ss +0*00 GET /page.html /1.1 200 3904 .from./from.htm Mozilla/4.0 (patible; MSIE 5.01; Windows NT 5.0) mod_gzip: 66pct.格式定义 :LogFormat=%host %other %logname %time1 %methodurl %code %bytesd %refererquot %uaqu ot %other %gzipratio日志记录如下所示 (NCSA bined and mod_gzip format 2
6、 with Apache 1.*):62.161.78.73 - - dd/mmm/yyyy:hh:mm:ss +0*00 GET /page.html /1.1 200 3904 .from./from.htm Mozilla/4.0 (patible; MSIE 5.01; Windows NT 5.0) mod_gzip: DECHUNK:OK In:11393 Out:3904:66pct.格式定义 :LogFormat=%host %other %logname %time1 %methodurl %code %bytesd %refererquot %uaqu ot %other
7、%other %gzipin %gzipout日志记录如下所示 (NCSA bined and mod_deflate with Apache 2):62.161.78.73 - - dd/mmm/yyyy:hh:mm:ss +0*00 GET /page.html /1.1 200 3904 .from./from.htm Mozilla/4.0 (patible; MSIE 5.01; Windows NT 5.0) (45)格式定义 :LogFormat=%host %other %logname %time1 %methodurl %code %bytesd %refererquot
8、%uaqu ot %deflateratio日志记录如下所示 (NCSA bined with 2 spaces between some fields withZope):62.161.78.73 - - dd/mmm/yyyy:hh:mm:ss +0*00 GET /page.html /1.1 200 3904 .from./from.htm Mozilla/4.0 (patible; MSIE 5.01; Windows NT 5.0) (45)格式定义 :LogFormat=%host %other %logname %time1 %methodurl %code %bytesd %
9、refererquot %uaquotLogSeparator= *日志记录如下所示 (NCSA mon CLF log format):62.161.78.73 - - dd/mmm/yyyy:hh:mm:ss +0*00 GET /page.html/1.1 200 1234格式定义 : LogFormat=4 备注:这种格式的数据没有浏览器, 操作系统,关键词以及来源网页等特性统计日志记录如下所示(With someSquidversions, after setting emulate_log to on):200.135.30.181 - - dd/mmm/yyyy:hh:mm:ss
10、 +0*00 GET .mydomain./page.html/1.0 200 456TCP_CLIENT_REFRESH_MISS:DIRECT格式定义 : LogFormat=%host %other %logname %time1 %methodurl %code %bytesd %other日志记录如下所示 (Some old IIS W3C log format):yyyy-mm-dd hh:mm:ss 62.161.78.73 - GET /page.html 200 1234/1.1.z.-Mozilla/4.0+(patible;+MSIE+5.01;+Windows+NT+5
11、.0) .from./from.html格式定义 : LogFormat=2日志记录如下所示 (Some IIS W3C log format with some .net servers):yyyy-mm-dd hh:mm:ss GET /page.html - 62.161.78.73 -Mozilla/4.0+(patible;+MSIE+5.01;+Windows+NT+5.0) .from./from.html 200 1234/1.1格式定义 : LogFormat=2 (orLogFormat=%time2 %method %url %logname %host %other %
12、ua %referer %code %bytesd %oth er)日志记录如下所示 (Some IIS 6+ W3C log format):yyyy-mm-dd hh:mm:ss GET /page.html - 62.161.78.73 - Mozilla/4.0+(patible;+MSIE+5.01;+Windows+NT+5.0) .from./from.html 200 1234格式定义 : LogFormat=2 (or LogFormat=date time cs-method cs-uri-stem cs-username c-ip cs-version cs(User-A
13、gent) cs(Referer) sc-status sc-bytes) 日志记录如下所示 (Some ISA W3C log format):62.161.78.73, anonymous, Mozilla/4.0 (patible; MSIE 6.0; Windows NT 5.1), N, 1/1/2001, 0:00:16, W3ReversePro*y, HCSERV2, -, .host.be, 192.168.141.101, 80, 266, 406, 10042, , TCP, GET, 192.168.141.101/, te*t/html, Inet, 200, 0*4
14、2330010, -, -格式定义 :LogFile=sed -e s/, /t/g /yourlogpath/yourlogfile.log |LogFormat=2LogSeparator= 日志记录如下所示 (With some WebSite versions):yyyy-mm-dd hh:mm:ss 62.161.78.73 - 192.168.1.1 80 GET /page.html - 200 11205 0 0 /1.1 mydomain. Mozilla/4.0+(patible;+MSIE+5.5;+Windows+98) - .from./from.html格式定义 :LogFormat=%time2 %host %logname %other %other %method %url %other %code %bytesd %ot her %other %other %other %ua %other %referer日志记录如下所示 (Webstar native log format):05/21/00 0