Command Line Query

The simplest way to access the archive data is with the zgrep command. This command is identical to the commonly used grep command, except it is used for searching within gzipped files.

A simple query example is as follows:

"Show me all raw events from my Cisco 3750 switch where an interface was unplugged or plugged."

You can change directories to the date you're interested in, and then change to the ES directory and run the following command:

zgrep "LINK-3-UPDOWN" rm*

This command results in the following output:

rm-4220-422-0_2007-01-03-00-33-47_2007-01-03-00-44-01.gz:39967070»01/03/2007 00:38:13»3750»<187>26: 3d12h: %LINK-3-UPDOWN: Interface FastEthernet1/0/4, changed state to down»»

rm-4220-422-0_2007-01-03-00-33-47_2007-01-03-00-44-01.gz:39967073»01/03/2007 00:38:17»3750»<187>27: 3d12h: %LINK-3-UPDOWN: Interface FastEthernet1/0/4, changed state to up»»

Now, zgrep (and grep) are case-sensitive unless you specify otherwise, so the following would make an easier search and not be case-sensitive:

However, the most power is achieved when you use the regular expression capabilities, as demonstrated here:

zgrep -i -P "link-3-updown" /nfs/mars-lc/2007-01-0[1-7]/ES/rm*

This command allows you to use a case-insensitive search and specify a date range. In this example, you're looking for the message in the first seven days of January 2007. You can also use regular expressions for the string you're searching for.

You can find documentation on the use of regular expressions at the Perl Compatible Regular Expressions (PCRE) website: http://www.pcre.org/pcre.txt.

Was this article helpful?

0 0