【问题标题】:Powershell pull last 5 minutes of data from CSVPowershell 从 CSV 中提取最后 5 分钟的数据
【发布时间】:2022-11-30 01:33:35
【问题描述】:

我有一个每五分钟生成一次新数据的日志文件,我试图提取日志文件的最后五分钟并从最后五分钟提取特定数据。目前我有代码将其从 .log 转换为 .csv,标题为“日期、时间、Error1、Error2、Error3”。但是,到目前为止我尝试过的每一次尝试都没有正确提取数据。

CSV 的日期和时间格式为:“dd/MM/yyyy”,“hh:mm:ss.ms”

Powershell 不会给出任何可见的错误,但不会生成 errorCOLLECTION.csv

我的当前代码:

Copy-Item -Path "C:\ProgramData\Blah\Blah\Blah Blah\error.log" -Destination "C:\Windows\Blah\Blah\Logs\Temp\Blah Blah\" -PassThru
    
    Import-Csv "C:\Windows\Blah\Blah\Logs\Temp\Blah Blah\error.log" -delimiter "," -Header Date, Time, Error1, Error2, Error3 |
    Export-Csv -NoTypeInformation "C:\Windows\Blah\Blah\Logs\Temp\Blah Blah\error.csv"
    
    
    $referenceTime = '{0:dd/MM/yyyy,HH:mm:ss.ms}' -f (Get-Date '2019/02/25,19:09:00.590').AddMinutes(-5)
    $regexSearch   = '\bSdata:\s*\[(\d{2})]'
    
    switch -Regex -File "C:\Windows\Blah\Blah\Logs\Temp\Blah Blah\error.csv" {
        $regexSearch { 
            if (($_ -split ',')[0] -gt $referenceTime) { 
                set-content "C:\Windows\Blah\Blah\Logs\Temp\Blah Blah\errorCOLLECTION.csv"
            }
        }
    }

响应 Theo 的日志文件示例:

29/11/2022,10:48:48.693,PINSP,DC,<PID>6324</PID><TID>2996</TID><F>INFO_GET_KEY_DETAIL</F><X>lpszKeyName [CommsKey]</X><SF>key_lib.cpp</SF><SL>1177</SL>
29/11/2022,10:48:48.693,MDMSP,DC,<PID>6200</PID><TID>5772</TID><G><X>W</X><HS>65535</HS><RI>0</RI></G><F>SXIO::ReceiveIOMessage</F><AR><AN>RetrieveMessage</AN><RV><I4>0</I4></RV><P><N>szMessage</N><S>messageCategory: 0x3 messageType: 0x554cc006 messageID: 0xd6d7928</S></P><P><N>response</N><S>hservice: 43 ucClass: 3 usTLen: 4 TData: [33 01 00 12] ucSLen: 1 SData: [00] ucMLen: 0 ucRSlen: 0 ucRClen: 0</S></P></AR><SF>SXIO.cpp</SF><SL>833</SL>
29/11/2022,10:48:48.693,PINSP,DC,<PID>6324</PID><TID>2996</TID><F>INFO_GET_KEY_DETAIL</F><X>Return Value [0]</X><X>lptKeyDetail [caKeyName [CommsKey] usKeyId [2] usKeyspaceId [4] wTypeOfAccess [0x2] bIsIV [0] bMasterKey [0] bLoadedFlag [1] bIsDouble [0]]</X><SF>key_lib.cpp</SF><SL>1214</SL>
29/11/2022,10:48:48.693,PINSP,DC,<PID>6324</PID><TID>2996</TID><F>INFO_GET_KEY_DETAIL</F><X>lpszKeyName [MACKey]</X><SF>key_lib.cpp</SF><SL>1177</SL>
29/11/2022,10:48:48.693,PINSP,DC,<PID>6324</PID><TID>2996</TID><F>INFO_GET_KEY_DETAIL</F><X>Return Value [0]</X><X>lptKeyDetail [caKeyName [MACKey] usKeyId [3] usKeyspaceId [3] wTypeOfAccess [0x4] bIsIV [0] bMasterKey [0] bLoadedFlag [0] bIsDouble [1]]</X><SF>key_lib.cpp</SF><SL>1214</SL>
29/11/2022,10:48:48.694,PINSP,DC,<PID>6324</PID><TID>2996</TID><F>INFO_GET_KEY_DETAIL</F><X>lpszKeyName [PEKey]</X><SF>key_lib.cpp</SF><SL>1177</SL>
29/11/2022,10:48:48.694,PINSP,DC,<PID>6324</PID><TID>2996</TID><F>INFO_GET_KEY_DETAIL</F><X>Return Value [0]</X><X>lptKeyDetail [caKeyName [PEKey] usKeyId [4] usKeyspaceId [4] wTypeOfAccess [0x2] bIsIV [0] bMasterKey [0] bLoadedFlag [0] bIsDouble [1]]</X><SF>key_lib.cpp</SF><SL>1214</SL>
29/11/2022,10:48:48.694,PINSP,FW,<PID>6324</PID><TID>2996</TID><G><X>W</X><HS>44</HS><RI>2267</RI></G><F>PostWFSResult</F><F>WFSResultData</F><P><N>hWnd</N><PT>263508</PT></P><P><N>lpWFSResult->RequestID</N><U4>2267</U4></P><P><N>lpWFSResult->hService</N><U4>44</U4></P><P><N>lpWFSResult->hResult</N><H>0</H></P><P><N>lpWFSResult->u.dwCommandCode</N><U4>401</U4></P><P><N>lpStatus</N><OB><M><N>fwDevice</N><U2>0</U2></M><M><N>fwEncStat</N><U2>0</U2></M><M><N>lpszExtra</N><PT>00000000</PT></M><M><N>guidlight</N><S>0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0</S></M><M><N>fwAutoBeepMode</N><U2>2</U2></M><M><N>dwCertificateState</N><U4>4</U4></M><M><N>wDevicePosition</N><U2>3</U2></M><M><N>usPowerSaveRecoveryTime</N><U2>0</U2></M><M><N>wAntiFraudModule</N><U2>0</U2></M></OB></P><SF>FWResultImpl.cpp</SF><SL>4638</SL><E>WFS_GETINFO_COMPLETE</E>
29/11/2022,10:48:48.697,PINSP,FW,<PID>6324</PID><TID>2996</TID><G><X>W</X><HS>44</HS><RI>2268</RI></G><F>PostWFSResult</F><F>WFSResultData</F><P><N>hWnd</N><PT>7014346</PT></P><P><N>lpWFSResult->RequestID</N><U4>2268</U4></P><P><N>lpWFSResult->hService</N><U4>44</U4></P><P><N>lpWFSResult->hResult</N><H>0</H></P><P><N>lpWFSResult->u.dwCommandCode</N><U4>408</U4></P><SF>FWResultImpl.cpp</SF><SL>4638</SL><E>WFS_GETINFO_COMPLETE</E>
29/11/2022,10:48:48.702,Mgr,Mgr,<PID>6324</PID><TID>6588</TID><G><HS>44</HS></G><F>WFSGetInfo</F><P><N>*lppResult</N><OB><M><N>RequestID</N><U4>2268</U4></M><M><N>hService</N><U2>44</U2></M><M><N>hResult</N><U4>0</U4></M><M><N>Code</N><U4>408</U4></M><M><N>lpBuffer</N><PT>280E284D</PT></M></OB></P><RV><H>0</H></RV><SF>MgrApi.cpp</SF><SL>1394</SL>
29/11/2022,10:48:48.702,Mgr,Mgr,<PID>6324</PID><TID>6588</TID><G><HS>0</HS></G><F>WFSFreeResult</F><P><N>lpResult</N><OB><M><N>RequestID</N><U4>2268</U4></M><M><N>hService</N><U2>44</U2></M><M><N>hResult</N><U4>0</U4></M><M><N>Code</N><U4>408</U4></M><M><N>lpBuffer</N><PT>280E284D</PT></M></OB></P><SF>MgrApi.cpp</SF><SL>1230</SL>
29/11/2022,10:48:48.702,Mgr,Mgr,<PID>6324</PID><TID>6588</TID><G><HS>0</HS></G><F>WFSFreeResult</F><RV><H>0</H></RV><SF>MgrApi.cpp</SF><SL>1240</SL>
29/11/2022,10:48:48.703,Mgr,Mgr,<PID>6324</PID><TID>6588</TID><G><HS>0</HS></G><F>WFSFreeResult</F><P><N>lpResult</N><OB><M><N>RequestID</N><U4>2266</U4></M><M><N>hService</N><U2>49</U2></M><M><N>hResult</N><U4>0</U4></M><M><N>Code</N><U4>301</U4></M><M><N>lpBuffer</N><PT>08120D85</PT></M></OB></P><SF>MgrApi.cpp</SF><SL>1230</SL>
29/11/2022,10:48:48.703,Mgr,Mgr,<PID>6324</PID><TID>6588</TID><G><HS>0</HS></G><F>WFSFreeResult</F><RV><H>0</H></RV><SF>MgrApi.cpp</SF><SL>1240</SL>
29/11/2022,10:48:48.703,Mgr,Mgr,<PID>6324</PID><TID>6588</TID><G><HS>0</HS></G><F>WFSFreeResult</F><P><N>lpResult</N><OB><M><N>RequestID</N><U4>2267</U4></M><M><N>hService</N><U2>44</U2></M><M><N>hResult</N><U4>0</U4></M><M><N>Code</N><U4>401</U4></M><M><N>lpBuffer</N><PT>281523A5</PT></M></OB></P><SF>MgrApi.cpp</SF><SL>1230</SL>
29/11/2022,10:48:48.703,Mgr,Mgr,<PID>6324</PID><TID>6588</TID><G><HS>0</HS></G><F>WFSFreeResult</F><RV><H>0</H></RV><SF>MgrApi.cpp</SF><SL>1240</SL>

【问题讨论】:

  • 你为什么使用“拆分”。 Import-Csv 将删除逗号。
  • 好吧,如果您没有给文件任何要设置的内容,它为什么会生成文件?
  • 你做$referenceTime的方式只是给你一个细绳,而不是要与之比较的 DateTime 对象。然后您尝试将其与另一个字符串进行比较,但由于您使用的日期格式不可排序,因此您无法正确处理。接下来,为什么要创建一个中间 CSV 文件,然后在上面使用 switch -File?这将逐行读取文件并且不进行任何对象解析。如果您需要帮助,请edit您的问题并向我们展示一些日志文件
  • 请您再次编辑,因为现在您已将您的示例格式化为 1234565,这会删除其中似乎存在的标签。只是原始文本就可以了,前面是一行三重反引号,并以一行三重反引号结束。
  • 在 java 框中添加文本(有 <> ),这样数据就不会改变。

标签: powershell csv


【解决方案1】:

对您的代码稍作修改,因为 ($_ -split ',')[0] 只会针对日期而不是时间,以下内容适合我输出以以下内容开头的行:

29/11/2022,10:48:48.693,MDMSP,DC,<PID>6200...

我还使用 DateTime.TryParse 将这些字符串转换为 DateTime instance,老实说,我不确定将这些字符串作为字符串进行比较是否正确,至少将它们转换为 DateTime 实例我们 100% 确定比较将是正确的。

除此之外,正如其他用户在 cmets 中指出的那样,Set-Content 目前具有输出路径但没有值作为参数。

& {
    $referenceTime = (Get-Date '2019/02/25,19:09:00.590').AddMinutes(-5)
    $regexSearch   = 'Sdata:s*[(d{2})]'
    $parsedDate    = [ref] [datetime]::new(0)
    
    switch -Regex -File 'C:lalaerror.csv' {
        $regexSearch {
            $success = [datetime]::TryParseExact(
                ('{0},{1}' -f $_.Split(',')[0, 1]),
                'dd/MM/yyyy,HH:mm:ss.fff',
                [cultureinfo]::InvariantCulture,
                [System.Globalization.DateTimeStyles]::AssumeLocal,
                $parsedDate
            )
    
            if($success -and $parsedDate.Value -gt $referenceTime) {
                $_
            }
        }
    }
} | Set-Content 'C:lalaerrorCOLLECTION.csv'

【讨论】:

    猜你喜欢
    • 2018-10-31
    • 1970-01-01
    • 1970-01-01
    • 2021-10-14
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2018-12-10
    • 1970-01-01
    相关资源
    最近更新 更多