Host Log Parser
Reported by candidates from Verkada's online assessment. Pattern, common pitfall, and the honest play if you blank under the timer.
Verkada reportedly put the Host Log Parser in an OA in September 2026, and the whole thing hinges on a character-by-character scanner with a small state machine, not a regex or a split. If you have the invite and 48 hours, this is the one to understand. You parse each log line left to right, grab a timestamp that's either one token or two, then pull out key=value fields where values can be quoted, empty, or full of equal signs and escaped quotes. It's string parsing with traps. StealthCoder is the safety net if you freeze on the live OA, but the logic below is short enough to own.
The problem
Parse host log lines into structured fields while processing each line from left to right. A non-blank line begins with either a no-space ISO timestamp or a timestamp in the form YYYY-MM-DD HH:mm:ss.SSS. The remainder contains whitespace-delimited key=value fields. Keys contain only letters, digits, underscore, dot, or hyphen. An unquoted value ends at whitespace. A quoted value may contain spaces and equal signs, supports \" as an escaped quote, and may be empty. For every non-blank line, return one row whose first element is the complete timestamp and whose remaining elements are normalized key=value strings in source order. Remove surrounding quotes and replace each escaped quote with a literal quote. Skip blank lines. Function parseHostLogs(lines: String[]) → String[][] Examples Example 1 lines = ["2026-09-29T10:20:30Z host=api-1 status=ok","2026-09-29 10:20:31.123 msg=\"retry later\" code=503"] return = [["2026-09-29T10:20:30Z","host=api-1","status=ok"],["2026-09-29 10:20:31.123","msg=retry later","code=503"]] The second timestamp spans two tokens, while the quoted message remains one value. Example 2 lines = ["2026-01-01T00:00:00Z note=\"a=b and \\\"quoted\\\"\" empty=\"\""] return = [["2026-01-01T00:00:00Z","note=a=b and \"quoted\"","empty="]] Equal signs and escaped quotes inside a quoted value are preserved. Example 3 lines = [""," ","2026-05-06 07:08:09.010 a=1\tb=two"] return = [["2026-05-06 07:08:09.010","a=1","b=two"]] Blank lines are skipped and tabs delimit fields. Constraints 0 <= lines.length <= 100000. Each line has at most 10000 characters. Every non-blank line follows the stated grammar. Fields are separated by one or more spaces or tabs.
Reported by candidates. Source: FastPrep
Pattern and pitfall
The trick is a single pointer scan with two modes: outside a quote and inside a quote. First skip whitespace. If the line has a space between the date and time (the second token looks like HH:mm:ss.SSS), join the first two tokens as the timestamp. Then loop: read the key up to the first equals sign, then check the next char. If it's a quote, consume until an unescaped quote, turning backslash-quote into a literal quote. Otherwise read until whitespace. Pitfalls: splitting on spaces breaks quoted values, splitting on equals breaks values like a=b, and an empty quoted value must yield key= with nothing after it. Also treat spaces and tabs the same, and skip lines that are blank after trimming. With 100000 lines of 10000 chars, stay linear per line. If you blank during the OA, StealthCoder can feed you the scanner skeleton.
The honest play: practice the pattern, and have StealthCoder ready for the one you didn't see coming.
You can drill Host Log Parser cold, or you can hedge it. StealthCoder runs invisibly during screen share and surfaces a working solution in under 2 seconds. The proctor sees the IDE. They don't see what's behind it. Built for the candidate who saw this exact problem leak two days before his OA and wondered if anyone had a play.
Get StealthCoderRelated leaked OAs
You've seen the question.
Make sure you actually pass Verkada's OA.
Verkada reuses patterns across OAs. Built for the candidate who saw this exact problem leak two days before his OA and wondered if anyone had a play. Works on HackerRank, CodeSignal, CoderPad, and Karat.
Host Log Parser FAQ
What's the trick in the Verkada Host Log Parser?+
Don't split. Walk the line with an index and a quote-state flag. Outside quotes, whitespace ends a token. Inside quotes, only an unescaped quote ends the value. That one idea handles spaces, equals signs, and empty values without any regex gymnastics.
How do I tell which timestamp format a line uses?+
Read the first token. If it contains a T, it's the ISO form and stands alone. If it's a plain YYYY-MM-DD date, the next token is the time part, so join them with a single space. The examples show the output keeps that space in the timestamp.
How should I handle escaped quotes inside a quoted value?+
While scanning inside quotes, when you see a backslash followed by a quote, append just the quote and advance two characters. Otherwise append the character as is. When you hit a bare quote, the value is done. Don't strip quotes with a replace afterward, it'll corrupt escapes.
What edge cases should I test before submitting?+
Test blank and whitespace-only lines, tab-separated fields, an empty quoted value like empty="", a value containing equals signs, multiple spaces between fields, and a line with only a timestamp. Also check the output order matches source order for every field.
How do I prepare for this in 48 hours?+
Write the scanner once from scratch using the three examples as tests. Practice similar tokenizer problems like CSV parsing or string decoding. Focus on index management and state flags. If you can pass example 2 cleanly, you've covered most of the hard cases.