Skip to content

Instantly share code, notes, and snippets.

What would you like to do?
# Read from journalctl outputting json and sort the data by program frequency
# Author: Kyle Manna
# invocation: journalctl -o json --since "1 month ago" | jq -s -f systemd-journalctl-sort-by-program-frequency.jq
# Grab the most useful name and a pointer/cursor to each occurrence
[.[] | { name: (if .SYSLOG_IDENTIFIER then .SYSLOG_IDENTIFIER else ._COMM end), cursor:.__CURSOR }]
# Group by name
| group_by(.name)
# Collapse the grouping in to a simple { name: $NAME, length: XX } object
| map({name: .[0].name, length: [.[].cursor] | length})
# Sort by length
| sort_by(.length)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment