Python pyinotify日誌監控系統處理日誌的方法,pythonpyinotify
前言
最近項目中遇到一個用於監控記錄檔的Python包pyinotify,結合自己的項目經驗和網上的一些資料總結一下,總的原理是利用pyinotify模組監控記錄檔夾,當日誌到來的情況下,觸發相應的函數進行處理,處理完畢後刪除記錄檔的過程,下面就著重介紹下pyinotify
pyinotify
Pyinotify是一個Python模組,用來監測檔案系統的變化。 Pyinotify依賴於Linux核心的功能—inotify(核心2.6.13合并)。 inotify的是一個事件驅動的通知器,其通知介面通過三個系統調用從核心空間到使用者空間。pyinotify結合這些系統調用,並提供一個頂級的抽象和一個通用的方式來處理這些功能。
- pyinotify 說百了就是通過 調用系統的inotify來實現通知的
- inotify 既可以監視檔案,也可以監視目錄
- Inotify 使用系統調用而非 SIGIO 來通知檔案系統事件。
Inotify 可以監視的檔案系統事件包括:
| Event Name |
Is an Event |
Description |
| IN_ACCESS |
Yes |
file was accessed. |
| IN_ATTRIB |
Yes |
metadata changed. |
| IN_CLOSE_NOWRITE |
Yes |
unwrittable file was closed. |
| IN_CLOSE_WRITE |
Yes |
writtable file was closed. |
| IN_CREATE |
Yes |
file/dir was created in watched directory. |
| IN_DELETE |
Yes |
file/dir was deleted in watched directory. |
| IN_DELETE_SELF |
Yes |
自刪除,即一個可執行檔在執行時刪除自己 |
| IN_DONT_FOLLOW |
No |
don't follow a symlink (lk 2.6.15). |
| IN_IGNORED |
Yes |
raised on watched item removing. Probably useless for you, prefer instead IN_DELETE*. |
| IN_ISDIR |
No |
event occurred against directory. It is always piggybacked to an event. The Event structure automatically provide this information (via .is_dir) |
| IN_MASK_ADD |
No |
to update a mask without overwriting the previous value (lk 2.6.14). Useful when updating a watch. |
| IN_MODIFY |
Yes |
file was modified. |
| IN_MOVE_SELF |
Yes |
自移動,即一個可執行檔在執行時移動自己 |
| IN_MOVED_FROM |
Yes |
file/dir in a watched dir was moved from X. Can trace the full move of an item when IN_MOVED_TO is available too, in this case if the moved item is itself watched, its path will be updated (see IN_MOVE_SELF). |
| IN_MOVED_TO |
Yes |
file/dir was moved to Y in a watched dir (see IN_MOVE_FROM). |
| IN_ONLYDIR |
No |
only watch the path if it is a directory (lk 2.6.15). Usable when calling .add_watch. |
| IN_OPEN |
Yes |
file was opened. |
| IN_Q_OVERFLOW |
Yes |
event queued overflowed. This event doesn't belongs to any particular watch. |
| IN_UNMOUNT |
Yes |
宿主檔案系統被 umount |
IN_ACCESS,即檔案被訪問
IN_MODIFY,檔案被write
IN_ATTRIB,檔案屬性被修改,如chmod、chown、touch等
IN_CLOSE_WRITE,可寫檔案被close
IN_CLOSE_NOWRITE,不可寫檔案被close
IN_OPEN,檔案被open
IN_MOVED_FROM,檔案被移走,如mv
IN_MOVED_TO,檔案被移來,如mv、cp
IN_CREATE,建立新檔案
IN_DELETE,檔案被刪除,如rm
IN_DELETE_SELF,自刪除,即一個可執行檔在執行時刪除自己
IN_MOVE_SELF,自移動,即一個可執行檔在執行時移動自己
IN_UNMOUNT,宿主檔案系統被umount
IN_CLOSE,檔案被關閉,等同於(IN_CLOSE_WRITE | IN_CLOSE_NOWRITE)
IN_MOVE,檔案被移動,等同於(IN_MOVED_FROM | IN_MOVED_TO)
pyinotify使用例子
#!/usr/bin/python# coding:utf-8import osfrom pyinotify import WatchManager, Notifier,ProcessEvent,IN_DELETE, IN_CREATE,IN_MODIFYclass EventHandler(ProcessEvent): """事件處理""" def process_IN_CREATE(self, event): print "Create file: %s " % os.path.join(event.path,event.name) def process_IN_DELETE(self, event): print "Delete file: %s " % os.path.join(event.path,event.name) def process_IN_MODIFY(self, event): print "Modify file: %s " % os.path.join(event.path,event.name) def FSMonitor(path='.'): wm = WatchManager() mask = IN_DELETE | IN_CREATE |IN_MODIFY notifier = Notifier(wm, EventHandler()) wm.add_watch(path, mask,auto_add=True,rec=True) print 'now starting monitor %s'%(path) while True: try: notifier.process_events() if notifier.check_events(): notifier.read_events() except KeyboardInterrupt: notifier.stop() breakif __name__ == "__main__": FSMonitor('/root/softpython/apk_url')
以上就是本文的全部內容,希望對大家的學習有所協助,也希望大家多多支援幫客之家。