lnav/README.md

131 lines
4.5 KiB
Markdown
Raw Normal View History

2013-04-10 05:36:08 +00:00
[![Build Status](https://travis-ci.org/tstack/lnav.png)](https://travis-ci.org/tstack/lnav)
2016-06-04 19:52:32 +00:00
[![Build status](https://ci.appveyor.com/api/projects/status/24wskehb7j7a65ro?svg=true)](https://ci.appveyor.com/project/tstack/lnav)
2020-09-23 21:51:11 +00:00
[![lnav](https://snapcraft.io//lnav/badge.svg)](https://snapcraft.io/lnav)
2016-12-24 20:57:46 +00:00
[![LoC](https://tokei.rs/b1/github/tstack/lnav)](https://github.com/tstack/lnav).
2013-04-10 05:36:08 +00:00
_This is the source repository for **lnav**, visit [http://lnav.org](http://lnav.org) for a high level overview._
2017-05-09 18:02:38 +00:00
# LNAV -- The Logfile Navigator
2013-04-10 05:36:08 +00:00
The Log File Navigator, **lnav** for short, is an advanced log file viewer
for the small-scale. It is a terminal application that can understand
your log files and make it easy for you to find problems with little to
no setup.
### Links
* [Main Site](https://lnav.org)
* [**Documentation**](https://lnav.readthedocs.io) on Read the Docs
## Contributing
2013-04-10 05:36:08 +00:00
2019-10-21 22:53:58 +00:00
[Become a Sponsor on GitHub](https://github.com/sponsors/tstack)
2013-04-10 05:36:08 +00:00
## Features
* Log messages from different files are collated together into a single view
* Automatic detection of log format
* Automatic decompression of GZip and BZip2 files
* Filter log messages based on regular expressions
* Use SQL to analyze your logs
* And more...
2017-05-09 18:02:38 +00:00
## Prerequisites
2013-04-10 05:36:08 +00:00
The following software packages are required to build lnav:
2013-04-10 05:36:08 +00:00
2020-09-12 21:06:23 +00:00
* gcc/clang - A C++14-compatible compiler.
* libpcre - The Perl Compatible Regular Expression (PCRE) library.
* sqlite - The SQLite database engine. Version 3.9.0 or higher is required.
* ncurses - The ncurses text UI library.
* readline - The readline line editing library.
* zlib - The zlib compression library.
* bz2 - The bzip2 compression library.
* libcurl - The cURL library for downloading files from URLs. Version 7.23.0 or higher is required.
2013-04-10 05:36:08 +00:00
2017-05-09 18:02:38 +00:00
## Installation
2013-04-10 05:36:08 +00:00
Lnav follows the usual GNU style for configuring and installing software:
$ ./configure
$ make
$ sudo make install
2017-04-19 10:36:22 +00:00
__Run `./autogen.sh` before running any of the above commands when
compiling from a cloned repository.__
2013-04-10 05:36:08 +00:00
2017-05-09 18:02:38 +00:00
## Cygwin users
It should compile fine in Cygwin.
2016-06-04 19:52:32 +00:00
Alternatively, you can get the generated binary from [AppVeyor](https://ci.appveyor.com/project/tstack/lnav) artifacts.
Remember that you still need the lnav dependencies under Cygwin, here is a quick way to do it:
2017-04-19 10:36:22 +00:00
setup-x86_64.exe -q -P libpcre1 -P libpcrecpp0 -P libsqlite3_0 -P libstdc++6
Currently, the x64 version seems to be working better than the x86 one.
2017-05-09 18:02:38 +00:00
## Usage
2013-04-10 05:36:08 +00:00
2017-04-19 10:36:22 +00:00
The only file installed is the executable, `lnav`. You can execute it
2013-04-10 05:36:08 +00:00
with no arguments to view the default set of files:
$ lnav
You can view all the syslog messages by running:
$ lnav /var/log/messages*
2017-05-09 18:02:38 +00:00
### Usage with `systemd-journald`
On systems running `systemd-journald`, you can use `lnav` as the pager:
$ journalctl | lnav
or in follow mode:
$ journalctl -f | lnav
Since `journalctl`'s default output format omits the year, if you are
viewing logs which span multiple years you will need to change the
output format to include the year, otherwise `lnav` gets confused:
$ journalctl -o short-iso | lnav
It is also possible to use `journalctl`'s json output format and `lnav`
2018-08-25 16:38:55 +00:00
will make use of additional fields such as PRIORITY and _SYSTEMD_UNIT:
$ journalctl -o json | lnav
2018-08-25 16:38:55 +00:00
In case some MESSAGE fields contain special characters such as
ANSI color codes which are considered as unprintable by journalctl,
specifying `journalctl`'s `-a` option might be preferable in order
to output those messages still in a non binary representation:
$ journalctl -a -o json | lnav
If using systemd v236 or newer, the output fields can be limited to
the ones actually recognized by `lnav` for increased efficiency:
$ journalctl -o json --output-fields=MESSAGE,PRIORITY,_PID,SYSLOG_IDENTIFIER,_SYSTEMD_UNIT | lnav
If your system has been running for a long time, for increased
efficiency you may want to limit the number of log lines fed into
`lnav`, e.g. via `journalctl`'s `-n` or `--since=...` options.
In case of a persistent journal, you may want to limit the number
of log lines fed into `lnav` via `journalctl`'s `-b` option.
2017-05-09 18:02:38 +00:00
## Screenshot
2013-04-10 05:36:08 +00:00
The following screenshot shows a syslog file. Log lines are displayed with
highlights. Errors are red and warnings are yellow.
[![Screenshot](http://tstack.github.io/lnav/lnav-syslog-thumb.png)](http://tstack.github.io/lnav/lnav-syslog.png)
2020-09-12 21:06:23 +00:00
## See Also
2013-04-10 05:36:08 +00:00
[Angle-grinder](https://github.com/rcoh/angle-grinder) is a tool to slice and dice log files on the command-line.
If you're familiar with the SumoLogic query language, you might find this tool more comfortable to work with.