Interview question summary: Host Log Parser (key-value pairs)
1. Background and goal
Background: host systems and IoT edge devices (such as network cameras, access controllers, gateways, and so on) continuously produce runtime logs. Every log line starts with the timestamp of the event, followed by some key-value pairs joined with an equals sign.
Goal: write a Python program that reads a log file and parses it into a structure, turning each line of text into a dict containing the timestamp and the key-value mapping of each field.
2. Log format spec and edge cases
<timestamp> <key1>=<val1> <key2>="<val 2 with spaces>" <key3>=<val3> ...
- Timestamp: it sits at the very start of each line. It is either an ISO-8601 timestamp with no spaces (e.g. 2026-09-29T22:15:30Z) or a standard date-time with a single space (e.g. 2026-09-29 22:15:31.450). After extraction it goes into the 'timestamp' key of the returned dict.
- Key: made up of letters, digits, underscores, hyphens, or dots (the rule is [\w.-]+), immediately followed by an equals sign.
- Value types and handling rules:
- Unquoted value: contains no spaces, and ends at a space or end of line (e.g. host=cam-01, status=failed, retries=3).
- Quoted value: wrapped in a matching pair of double quotes ("..."). Inside the quotes there can be spaces, several consecutive spaces, an inner equals sign (e.g. details="reboot=true"), or escaped double quotes. The output has to strip the outer double quotes and restore the escaped characters.
- Empty value: an empty string assignment has to be supported (e.g. note="" gives {'note': ''}).
- Separators and whitespace: one or more spaces/tabs (\s+) are allowed between key-value pairs. Empty lines and lines containing only whitespace have to be skipped automatically.
- File reading and performance constraint: for huge log files (multi-gigabyte), you must not load the whole thing into memory (no readlines()). You have to read in a streaming way (a generator) and keep auxiliary memory at O(1).
3. Typical test cases
Mixed types:
2026-09-29T22:15:30Z host=cam-01 event="camera offline" status=failed retries=3
{'timestamp': '2026-09-29T22:15:30Z', 'host': 'cam-01', 'event': 'camera offline', 'status': 'failed', 'retries': '3'}
Multiple consecutive spaces:
2026-09-29 22:15:31.450 host=gw-99 ip=192.168.1.1 msg="handshake failed: connection reset" code=500
{'timestamp': '2026-09-29 22:15:31.450', 'host': 'gw-99', 'ip': '192.168.1.1', 'msg': 'handshake failed: connection reset', 'code': '500'}
Escapes and nested symbols:
2026-09-29T22:15:33Z event="firmware update" details="version="2.4.1" reboot=true" note=""
{'timestamp': '2026-09-29T22:15:33Z', 'event': 'firmware update', 'details': 'version="2.4.1" reboot=true', 'note': ''}
Discussion
Loading comments…