Finding data in your logs.
Posted in 1999
Topics: General Discussion
> Can I now use onlog and search the logs and see this data?
Well, yes and no. You can use onlog to read through logical log records,
but it can be a challenge.
If I have the following logs (onstat -l):
address number flags uniqid begin size used %used
cab8f9a4 1 U---C-L 11 100427 500 386 77.20
cab8f9c0 2 F------ 0 10061b 500 0 0.00
cab8f9dc 3 F------ 0 10080f 500 0 0.00
cab8f9f8 4 F------ 0 100a03 500 0 0.00
cab8fa14 5 U-B---- 5 100bf7 500 500 100.00
cab8fa30 6 U-B---- 6 100deb 500 500 100.00
cab8fa4c 7 U-B---- 7 100fdf 500 500 100.00
cab8fa68 8 U-B---- 8 1011d3 500 500 100.00
cab8fa84 9 U-B---- 9 1013c7 500 500 100.00
cab8faa0 10 U-B---- 10 1015bb 500 500 100.00
I can issue the command: "onlog -l -n 10 | more", where -n is the uniqid of
the log, to display the log contents, including the actual record images
and what type of action it was (HINSERT,HDELETE,etc), but the images are in
hex and are quite unreadable if you have a lot of decimal, date, datetime,
or any other non-integer, non-character data in your table. Here is the
output for an insert statement:
addr len type xid id link
2f8 80 HINSERT 13 0 2c0 10008c d24 36
00000050 00000028 01120000 0000000d ...P...( ........
000002c0 0069d0b6 0010008c 0010008c .....i.. ........
00000d24 00240000 00000000 726d6b65 ...$.$.. ....rmke
79312020 20202020 20202020 20200000 y1 ..
00af0002 00020004 80000000 80000000 ........ ........
Word of caution (right from the course book): "When a log from disk is being
read, read and write access to that log is denied to other users." Reading
from the "C" current log will hold up users attempting to do work, so it's
best to leave this one alone.
This can be somewhat useful in identifying transactions and what action they
performed last, but to actually re-create a row based on what onlog will
show you is next to impossible. We had a group that deleted several
thousand rows by mistake from a production system and attempted to rebuild
them using onlog output, but it was a fruitless effort. They ended up using
a second machine to restore an archive from, then copy the data back into
the production database (this was actually EASIER to do vs. looking through
onlog output).
Have fun....
Keaton
> Thanks in advance
> david.tamburin@protegrity.com
> -----BEGIN PGP SIGNATURE-----
> Version: PGP Personal Privacy 6.0.2
>
> iQA/AwUBN2cKjCEUeYIwgiQNEQIqqACfefgro73/jMID6VQqUduNWcS1b/EAoOzk
> 0p/LSYqKl0k1JNnA+Nnu0Ynj
> =KbLM
> -----END PGP SIGNATURE-----
>
A couple of additional considerations.
1) If you are using buffered logging, the data might not yet be in the disk log
file. It could still be in the log buffer when the onlog command is run.
2) It's not a good idea to run onlog on the "current" log. It will hang the
instance until onlog is finished. To avoid this, run "onmode -l" before onlog
is run.
Keaton Adams wrote:
> > Can I now use onlog and search the logs and see this data?
>
> Well, yes and no. You can use onlog to read through logical log records,
> but it can be a challenge.
>
> If I have the following logs (onstat -l):
>
> address number flags uniqid begin size used %used
> cab8f9a4 1 U---C-L 11 100427 500 386 77.20
> cab8f9c0 2 F------ 0 10061b 500 0 0.00
> cab8f9dc 3 F------ 0 10080f 500 0 0.00
> cab8f9f8 4 F------ 0 100a03 500 0 0.00
> cab8fa14 5 U-B---- 5 100bf7 500 500 100.00
> cab8fa30 6 U-B---- 6 100deb 500 500 100.00
> cab8fa4c 7 U-B---- 7 100fdf 500 500 100.00
> cab8fa68 8 U-B---- 8 1011d3 500 500 100.00
> cab8fa84 9 U-B---- 9 1013c7 500 500 100.00
> cab8faa0 10 U-B---- 10 1015bb 500 500 100.00
>
> I can issue the command: "onlog -l -n 10 | more", where -n is the uniqid of
> the log, to display the log contents, including the actual record images
> and what type of action it was (HINSERT,HDELETE,etc), but the images are in
> hex and are quite unreadable if you have a lot of decimal, date, datetime,
> or any other non-integer, non-character data in your table. Here is the
> output for an insert statement:
>
> addr len type xid id link
> 2f8 80 HINSERT 13 0 2c0 10008c d24 36
> 00000050 00000028 01120000 0000000d ...P...( ........
> 000002c0 0069d0b6 0010008c 0010008c .....i.. ........
> 00000d24 00240000 00000000 726d6b65 ...$.$.. ....rmke
> 79312020 20202020 20202020 20200000 y1 ..
> 00af0002 00020004 80000000 80000000 ........ ........
>
> Word of caution (right from the course book): "When a log from disk is being
> read, read and write access to that log is denied to other users." Reading
> from the "C" current log will hold up users attempting to do work, so it's
> best to leave this one alone.
>
> This can be somewhat useful in identifying transactions and what action they
> performed last, but to actually re-create a row based on what onlog will
> show you is next to impossible. We had a group that deleted several
> thousand rows by mistake from a production system and attempted to rebuild
> them using onlog output, but it was a fruitless effort. They ended up using
> a second machine to restore an archive from, then copy the data back into
> the production database (this was actually EASIER to do vs. looking through
> onlog output).
>
> Have fun....
>
> Keaton
>
> > Thanks in advance
> > david.tamburin@protegrity.com
> > -----BEGIN PGP SIGNATURE-----
> > Version: PGP Personal Privacy 6.0.2
> >
> > iQA/AwUBN2cKjCEUeYIwgiQNEQIqqACfefgro73/jMID6VQqUduNWcS1b/EAoOzk
> > 0p/LSYqKl0k1JNnA+Nnu0Ynj
> > =KbLM
> > -----END PGP SIGNATURE-----
> >
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Hello all,
Is it possible to find data entered into the database by using the
onlog utility?
And if so how can you do it.
For example:
insert into employee values ("John Doe","manager");
Can I now use onlog and search the logs and see this data?
Thanks in advance
david.tamburin@protegrity.com
-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.0.2
iQA/AwUBN2cKjCEUeYIwgiQNEQIqqACfefgro73/jMID6VQqUduNWcS1b/EAoOzk
0p/LSYqKl0k1JNnA+Nnu0Ynj
=KbLM
-----END PGP SIGNATURE-----