# variable inside a variable

**URL:** <https://community.unix.com/t/variable-inside-a-variable/298440>\
**Category:** Shell Programming and Scripting\
**Created:** [November 2, 2011, 7:44am UTC](https://community.unix.com/t/variable-inside-a-variable/298440 "2011-11-02T07:44:37Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![anilcliff](https://community.unix.com/letter_avatar/anilcliff/32/5_5575768a8748004e209b776fc1b2916d.png) [@anilcliff](https://community.unix.com/u/anilcliff)\
**Post date:** [November 2, 2011, 7:44am UTC](https://community.unix.com/t/variable-inside-a-variable/298440/1 "2011-11-02T07:44:37Z")

</div>

I am trying manipulate variables inside a variable

```plaintext
root@server [~]# hour=`date | awk {'print $4'} | cut -d: -f 1`;lasthour=`expr $hour - 01`; lasthour=`printf %02d $lasthour`;grep "`date -I` $lasthour" /var/log/exim_mainlog |egrep -o 'dovecot_login[^]+' | sort|uniq -c|sort -nk 1
      8 dovecot_login:user1@domain.com
      4 dovecot_login:user2@domain.com

```

The above prints output in two lines. When I take that to a variable and analze each line, it becomes 4 lines. What I need is to check the count of each entry and output if count is more than a limit, say 5. So the below script should only display "8 [dovecot\_login:user1@domain.com](mailto:dovecot_login:user1@domain.com)"

```plaintext
root@server [~]# for i in $(hour=`date | awk {'print $4'} | cut -d: -f 1`;lasthour=`expr $hour - 01`; lasthour=`printf %02d $lasthour`;grep "`date -I` $lasthour" /var/log/exim_mainlog |egrep -o 'dovecot_login[^]+' | sort|uniq -c|sort -nk 1); do echo $i; done
8
dovecot_login:user1@domain.com
4
dovecot_login:user2@domain.com

```

---

<div class="post-metadata">

**Author:** ![vgersh99](https://community.unix.com/user_avatar/community.unix.com/vgersh99/32/14851_2.png) [@vgersh99](https://community.unix.com/u/vgersh99)\
**Post date:** [November 2, 2011, 8:01am UTC](https://community.unix.com/t/variable-inside-a-variable/298440/2 "2011-11-02T08:01:35Z")

</div>

I believe you're over-complicating the task with the use of so many tools - there could be a more graceful way to do all of it.  
Please provide a sample of your /var/log/exim\_mainlog file using [code tags](http://www.unix.com/misc.php?do=bbcode&#code) and a desired output with the explanation.

Also what happens for the mid-night hour - hour 0?

---

<div class="post-metadata">

**Author:** ![anilcliff](https://community.unix.com/letter_avatar/anilcliff/32/5_5575768a8748004e209b776fc1b2916d.png) [@anilcliff](https://community.unix.com/u/anilcliff)\
**Post date:** [November 2, 2011, 10:18am UTC](https://community.unix.com/t/variable-inside-a-variable/298440/3 "2011-11-02T10:18:15Z")

</div>

I got it corrected. If the count is more than 3, it will display it.

```nohighlight
hour=`date | awk {'print $4'} | cut -d: -f 1`;lasthour=`expr $hour - 01`; lasthour=`printf %02d $lasthour`;grep "`date -I` $lasthour" /var/log/exim_mainlog |egrep -o 'dovecot_login[^]+' | sort|uniq -c|sort -nk 1| while read login; do num=`echo $login | awk {'print $1'}`; if [$num -gt 3]; then echo $login;fi ; done
4 dovecot_login:user1@domain.net
4 dovecot_login:user2@domain.com
11 dovecot_login:user3@domain.com
27 dovecot_login:user4@domain.ca

```

---------- Post updated at 07:48 PM ---------- Previous update was at 07:36 PM ----------

I have corrected the midnight 00 issue. Here is the complete script

```nohighlight
#!/bin/sh

hour=`date | awk {'print $4'} | cut -d: -f 1`

if [$hour= '00']; then
        hour = 24
fi

lasthour=`expr $hour - 01`
lasthour=`printf %02d $lasthour`

grep "`date -I` $lasthour" /var/log/exim_mainlog |egrep -o 'dovecot_login[^]+' | sort|uniq -c|sort -nk 1| while read login
do
        num=`echo $login | awk {'print $1'}`
        if [$num -gt 3]; then
                echo $login
        fi
done

```
