Copy subsequent contents of a file from first occurance of grep

There is a file which logs all errors and alerts of the database called alert log. I have a requirement as follows:

  1. Check the current date and search for the first occurance of the current date in the alert log.

  2. As soon as the first occurance is found, copy the subsequent contents (till the end of file) of the alert log (including the first occurance line) to a temporary file.

  3. Then check for some errors for today.

How do I achieve the above? :confused:

TIA,

Regards,

Praveen

what have you tried ..so far..

Could you share...

Thanks
Sha

Why not just use the date command to build a string which matches the date format of your log file, and then grep for that?

@Shawn, I can not grep the date command lines because errors and alerts in the alert log are written below the line which contains the date. Below is the sample alert log file.

Now, anything that has "ORA-" is usually an error and I want to capture that for today's date. Hence, I need to copy the subsequent contents of today's date's first occurance.

Suppose today is Mar 4 2009, then when the first occurance of the line occurs, I would like to copy the contents of the alert log from the first occurance line to the end to a temporary file and then search for any errors in that temporary file.

Tue Mar  3 22:23:37 2009
Completed checkpoint up to RBA [0x39a7.2.10], SCN: 10372821759272
Tue Mar  3 22:34:40 2009
Incremental checkpoint up to RBA [0x39a7.29021.0], current log tail at RBA [0x39a7.38f7e.0]
Tue Mar  3 22:54:44 2009
Incremental checkpoint up to RBA [0x39a7.7c0bc.0], current log tail at RBA [0x39a7.7edfc.0]
Tue Mar  3 23:14:48 2009
Incremental checkpoint up to RBA [0x39a7.acb35.0], current log tail at RBA [0x39a7.b72f6.0]
Tue Mar  3 23:34:52 2009
Incremental checkpoint up to RBA [0x39a7.f4f6f.0], current log tail at RBA [0x39a7.fb55a.0]
Tue Mar  3 23:54:57 2009
Incremental checkpoint up to RBA [0x39a7.12598f.0], current log tail at RBA [0x39a7.1371ec.0]
Wed Mar  4 00:10:16 2009
ORA-00060: Deadlock detected. More info in file /opt/dbms/app/oracle/product/comtst/10.2.0/admin/COMTST_suomt05k/udump/comtst_ora_25663.trc.
Wed Mar  4 00:10:22 2009
ORA-00060: Deadlock detected. More info in file /opt/dbms/app/oracle/product/comtst/10.2.0/admin/COMTST_suomt05k/udump/comtst_ora_5983.trc.
Wed Mar  4 00:15:02 2009
Incremental checkpoint up to RBA [0x39a7.15fff7.0], current log tail at RBA [0x39a7.160c26.0]
Wed Mar  4 00:35:06 2009
Incremental checkpoint up to RBA [0x39a7.191204.0], current log tail at RBA [0x39a7.1a5c0c.0]
Wed Mar  4 00:55:10 2009
Incremental checkpoint up to RBA [0x39a7.1b67bb.0], current log tail at RBA [0x39a7.1b75a1.0]
Wed Mar  4 01:15:14 2009
Incremental checkpoint up to RBA [0x39a7.1c96f7.0], current log tail at RBA [0x39a7.1ca1ef.0]
Wed Mar  4 01:35:18 2009
Incremental checkpoint up to RBA [0x39a7.1cd31a.0], current log tail at RBA [0x39a7.1d1b92.0]
Wed Mar  4 01:38:03 2009
Beginning log switch checkpoint up to RBA [0x39a8.2.10], SCN: 10372886671282
Thread 1 advanced to log sequence 14760
  Current log# 8 seq# 14760 mem# 0: /opt/apps/comsdb/comtstdata/redo08a.log
  Current log# 8 seq# 14760 mem# 1: /opt/apps/comsdb/comtstdata/redo08b.log
Wed Mar  4 01:43:07 2009
Completed checkpoint up to RBA [0x39a8.2.10], SCN: 10372886671282
Wed Mar  4 01:55:25 2009
Incremental checkpoint up to RBA [0x39a8.1429a.0], current log tail at RBA [0x39a8.14980.0]
Wed Mar  4 02:15:30 2009
Incremental checkpoint up to RBA [0x39a8.24b0f.0], current log tail at RBA [0x39a8.255d4.0]
Wed Mar  4 02:35:34 2009
Incremental checkpoint up to RBA [0x39a8.280fe.0], current log tail at RBA [0x39a8.28d8a.0]
Wed Mar  4 02:55:38 2009
Incremental checkpoint up to RBA [0x39a8.4e2aa.0], current log tail at RBA [0x39a8.5200a.0]
Wed Mar  4 03:15:42 2009
Incremental checkpoint up to RBA [0x39a8.6231a.0], current log tail at RBA [0x39a8.6306b.0]

Hi,

Hope this may help you..

grep -A1 "`date +%a` `date +%b` `date +%d|sed 's/^0//g'`" inputlogfile|tail +2|head -1 > output_errordetails

Thanks
Sha

@Shahul,

Thanks a lot for your help and suggestion.

I have devised a method myself, which is not dissimilar to what you have suggested.

The logic I've used is:

  1. Get the line number of the first occurance of today's date.

  2. Use the more +linenumber command to get the contents of the alert log from the first occurance to the end of file and put it in a temp file.

ln_no=$(egrep -n "$(date | cut -d ' ' -f1-4)" ${ALERT_LOG} | head -1 | awk '{print $1}' | cut -d ':' -f1)
 
more +${ln_no} ${ALERT_LOG} > ${TMP_FILE}

egrep -i "ORA-" ${TMP_FILE} > ${ERR_FILE}
if [[ $? -eq 0 ]]; then
  mailx -s "$(hostname): ${curr_date}: Errors in ${ORACLE_SID} alert log" ${APPSDBA_MAIL_LIST} < ${ERR_FILE}
fi
 

Thanks all for your suggestions! This forum rocks!!! :cool:

Regards,

Praveen