LogParser -i:IISW3C -o:CSV "select cs-uri-stem,max(sc-bytes) into I:\XXXX\IISLOG\W3SVC2\out.csv from I:\XXXX\IISLOG\W3SVC2\*.log where cs-uri-stem like '%.aspx%' group by cs-uri-stem order by max(sc-bytes) DESC"
LogParser -i:IISW3C -o:CSV "select cs-uri-stem,max(sc-bytes) into I:\XXXX\IIS_LOG\out1.csv from I:\XXXX\IIS_LOG\*.log where cs-uri-stem like '%.aspx%' group by cs-uri-stem order by max(sc-bytes) DESC"
下面的命令统计IIS LOG里面每个URL 的最大接收字节。
LogParser -i:IISW3C -o:CSV "select cs-uri-stem,max(cs-bytes) into I:\XXXX\IIS_LOG\out2.csv from I:\XXXX\IIS_LOG\*.log where cs-uri-stem like '%.aspx%' group by cs-uri-stem order by max(cs-bytes) DESC"
下面的命令统计IIS LOG里面每个URL 的最大执行时间,最小执行时间以及平均执行时间。
LogParser -i:IISW3C -o:CSV "select cs-uri-stem,COUNT(*),AVG(time-taken), Min(time-taken),MAX(time-taken) into I:\XXXX\IIS_LOG\out6.csv from I:\XXXX\IIS_LOG\*.log where cs-uri-stem like '%.aspx%' group by cs-uri-stem order by AVG(time-taken) DESC"
识破网络攻击的法宝
LogParser -i:IISW3C select * from C:\WINDOWS\system32\LogFiles\W3SVC752518\*.log where cs-uri-query like '%cmd.exe%'