Using Rexx PARSE to Split Apache Log Lines Efficiently
Learn how Rexx’s PARSE instruction can turn a raw Apache log line into clearly named variables without writing loops or regular expressions.
21 Sept 2026, 00:18 UTC

Problem: extracting fields from a log line without regular expressions
When processing Apache access logs, each line contains several pieces of information – client IP, timestamp, request method, URL, protocol, status code and response size – separated by spaces and brackets. Writing a parser with multiple SUBSTR or WORD calls quickly becomes verbose and error‑prone, especially when the log format changes.
Thesis: the PARSE instruction offers a concise, readable way to map a template to variables
Rexx’s PARSE instruction takes a source string and a template that mixes literals, positional patterns and variable placeholders. It assigns the matching substrings to the named variables in a single statement, eliminating the need for loops or manual index calculations.
How PARSE works
The template is read left‑to‑right. Literals must match exactly in the source; positional patterns (like a number or a variable) consume characters up to the next literal or the end of the string. Variables in the template receive the consumed substring.
Example template for a common log line:
PARSE VAR line remote '-' '-' datetime '[' method url protocol ']' status bytesHere:
lineholds the whole log entry.- The first two hyphens match the literal '-' characters that separate the remote address from the remote logname and user fields (both are ignored).
remotereceives the client IP address.- The next literal '
[' starts the timestamp; everything up to the matching ']' goes intodatetime. - After the bracket, the method, URL and protocol are separated by spaces, so they fill
method,urlandprotocol. - Finally,
statusandbytescapture the numeric fields.
When the instruction runs, each variable contains the corresponding substring. No explicit conversion is needed because everything in Rexx is a string.
Worked example: parsing a sample log line
Consider the following line (typical combined log format):
127.0.0.1 - - [10/Oct/2026:13:55:36 +0000] "GET /index.html HTTP/1.1" 200 1024The PARSE statement above would assign:
remote→127.0.0.1datetime→10/Oct/2026:13:55:36 +0000method→GETurl→/index.htmlprotocol→HTTP/1.1status→200bytes→1024
If a field is missing (e.g., the user identifier), the corresponding variable receives an empty string, which can be tested with a simple IF var = '' THEN ... check.
Trade‑offs and limitations
PARSE excels at fixed‑delimiter or positional patterns, but it does not support full regular‑expression features such as alternation, look‑ahead or Unicode categories. For logs that require optional quoted fields with embedded spaces, a more complex template may become hard to read. In those cases, splitting the line into tokens first or using an external library (e.g., a PCRE binding) might be clearer.
Maintainability tip: keep the template close to the source line and add comments that explain each literal. When debugging, print the source string and the template side‑by‑side to verify alignment.
Verification steps
- Run the PARSE snippet with a mainstream Rexx interpreter (IBM Object Rexx, Regina Rexx or BRexx).
- Inspect the variables (e.g., with
SAY remote) to confirm they hold the expected substrings. - Compare the results against a reference implementation in another language (Python’s
splitor a regex) for a variety of log lines, including edge cases like extra spaces or missing fields. - To assess performance, time the parsing of a large file (e.g., 100 000 lines) using PARSE versus a loop‑based SUBSTR approach; the PARSE version should be comparable or faster.
Actionable closing
If you need to extract structured data from text that follows a regular pattern, start with Rexx PARSE. Write a template that mirrors the literal separators in your source, assign the pieces to meaningful variables, and test with a few representative lines. When the pattern stays simple, you’ll gain readability and often a speed advantage over manual substring loops. For more complex, irregular formats, consider complementing PARSE with token‑splitting or a dedicated parsing library.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.