cut -d ' ' -f1 log | sort | uniq -c | sort -nr | head
Say you need to follow accesses to a particular file? The following quick and dirty one-liner probably works well enough: tail -f log | grep --line-buffered file.pdf
How do you do that with json?Granted, as soon as your logs stop being a sequence of records (lines) with a fixed sequence of neatly delimited records, you will need something more than text. However, I still don't know of tools to work with json from the command line that are as concise, efficient, flexible and robust as the standard unix utilities for text.