Python pyinotify日誌監控系統處理日誌的方法,pythonpyinotify

來源:互聯網
上載者:User

Python pyinotify日誌監控系統處理日誌的方法,pythonpyinotify

前言

最近項目中遇到一個用於監控記錄檔的Python包pyinotify,結合自己的項目經驗和網上的一些資料總結一下,總的原理是利用pyinotify模組監控記錄檔夾,當日誌到來的情況下,觸發相應的函數進行處理,處理完畢後刪除記錄檔的過程,下面就著重介紹下pyinotify

pyinotify

Pyinotify是一個Python模組,用來監測檔案系統的變化。 Pyinotify依賴於Linux核心的功能—inotify(核心2.6.13合并)。 inotify的是一個事件驅動的通知器,其通知介面通過三個系統調用從核心空間到使用者空間。pyinotify結合這些系統調用,並提供一個頂級的抽象和一個通用的方式來處理這些功能。

  1. pyinotify 說百了就是通過 調用系統的inotify來實現通知的
  2. inotify 既可以監視檔案,也可以監視目錄
  3. Inotify 使用系統調用而非 SIGIO 來通知檔案系統事件。

Inotify 可以監視的檔案系統事件包括:

Event Name Is an Event Description
IN_ACCESS Yes file was accessed.
IN_ATTRIB Yes metadata changed.
IN_CLOSE_NOWRITE Yes unwrittable file was closed.
IN_CLOSE_WRITE Yes writtable file was closed.
IN_CREATE Yes file/dir was created in watched directory.
IN_DELETE Yes file/dir was deleted in watched directory.
IN_DELETE_SELF Yes 自刪除,即一個可執行檔在執行時刪除自己
IN_DONT_FOLLOW No don't follow a symlink (lk 2.6.15).
IN_IGNORED Yes raised on watched item removing. Probably useless for you, prefer instead IN_DELETE*.
IN_ISDIR No event occurred against directory. It is always piggybacked to an event. The Event structure automatically provide this information (via .is_dir)
IN_MASK_ADD No to update a mask without overwriting the previous value (lk 2.6.14). Useful when updating a watch.
IN_MODIFY Yes file was modified.
IN_MOVE_SELF Yes 自移動,即一個可執行檔在執行時移動自己
IN_MOVED_FROM Yes file/dir in a watched dir was moved from X. Can trace the full move of an item when IN_MOVED_TO is available too, in this case if the moved item is itself watched, its path will be updated (see IN_MOVE_SELF).
IN_MOVED_TO Yes file/dir was moved to Y in a watched dir (see IN_MOVE_FROM).
IN_ONLYDIR No only watch the path if it is a directory (lk 2.6.15). Usable when calling .add_watch.
IN_OPEN Yes file was opened.
IN_Q_OVERFLOW Yes event queued overflowed. This event doesn't belongs to any particular watch.
IN_UNMOUNT Yes 宿主檔案系統被 umount

IN_ACCESS,即檔案被訪問

IN_MODIFY,檔案被write

IN_ATTRIB,檔案屬性被修改,如chmod、chown、touch等

IN_CLOSE_WRITE,可寫檔案被close

IN_CLOSE_NOWRITE,不可寫檔案被close

IN_OPEN,檔案被open

IN_MOVED_FROM,檔案被移走,如mv

IN_MOVED_TO,檔案被移來,如mv、cp

IN_CREATE,建立新檔案

IN_DELETE,檔案被刪除,如rm

IN_DELETE_SELF,自刪除,即一個可執行檔在執行時刪除自己

IN_MOVE_SELF,自移動,即一個可執行檔在執行時移動自己

IN_UNMOUNT,宿主檔案系統被umount

IN_CLOSE,檔案被關閉,等同於(IN_CLOSE_WRITE | IN_CLOSE_NOWRITE)

IN_MOVE,檔案被移動,等同於(IN_MOVED_FROM | IN_MOVED_TO)

pyinotify使用例子

#!/usr/bin/python# coding:utf-8import osfrom pyinotify import WatchManager, Notifier,ProcessEvent,IN_DELETE, IN_CREATE,IN_MODIFYclass EventHandler(ProcessEvent): """事件處理""" def process_IN_CREATE(self, event): print "Create file: %s " % os.path.join(event.path,event.name) def process_IN_DELETE(self, event): print "Delete file: %s " % os.path.join(event.path,event.name) def process_IN_MODIFY(self, event): print "Modify file: %s " % os.path.join(event.path,event.name) def FSMonitor(path='.'): wm = WatchManager()  mask = IN_DELETE | IN_CREATE |IN_MODIFY notifier = Notifier(wm, EventHandler()) wm.add_watch(path, mask,auto_add=True,rec=True) print 'now starting monitor %s'%(path) while True: try:  notifier.process_events()  if notifier.check_events():  notifier.read_events() except KeyboardInterrupt:  notifier.stop()  breakif __name__ == "__main__": FSMonitor('/root/softpython/apk_url') 

以上就是本文的全部內容,希望對大家的學習有所協助,也希望大家多多支援幫客之家。

聯繫我們

該頁面正文內容均來源於網絡整理,並不代表阿里雲官方的觀點,該頁面所提到的產品和服務也與阿里云無關,如果該頁面內容對您造成了困擾,歡迎寫郵件給我們,收到郵件我們將在5個工作日內處理。

如果您發現本社區中有涉嫌抄襲的內容,歡迎發送郵件至: info-contact@alibabacloud.com 進行舉報並提供相關證據,工作人員會在 5 個工作天內聯絡您,一經查實,本站將立刻刪除涉嫌侵權內容。

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.