問題文
A report needs the number of requests per client address from a large access log. There is no need to see the individual events grouped together, only the counts. Which approach does the documentation recommend, and why?
選択肢
- Use the fillnull command to add a counting field and a client address label field to every raw web access log event row before the report.
- Use stats to count by the client address, because grouping events is not the efficient way to compute aggregate statistics.
- Use the transaction command grouped by the client address, because the count of events in each group is exactly the number of requests and no extra command is needed.
- Use the transaction command with a very large span, because that guarantees that every request from one address lands in a single group before the count is taken.