Exercise
Searching Log Files with grep Exercise
Task
In this hands-on exercise, investigate the SSH service
with grep by searching authentication logs,
checking service status, and refining command output.
- Target host
servera- Privileges
-
sudoaccess to read/var/log/secureand inspectsshd
-
Find matching log entries
Connect to
serveraand find SSH events in the root-only authentication log.ssh student@servera sudo grep 'sshd' /var/log/secureLimit the results to successful authentication.
sudo grep 'Accepted' /var/log/secure -
Show context around matches
Check the SSH service status, then use
-B2and-A3to keep the service identity, load state, and details around the active state.systemctl status sshd | grep -B2 -A3 'Active:' -
Refine results with grep options
Confirm that SSH processes are running. Notice that
grepalso finds its own process.ps ax | grep 'sshd'Pipe it into a second
grepwith-v, which prints every line that does not match.ps ax | grep 'sshd' | grep -v 'grep'Ask
sshdfor its effective configuration, then give-eonce for each setting to display.sudo sshd -T | grep -e '^port ' -e '^permitrootlogin 'Run the search twice and compare the results. Without
-i, the pattern misses every line that usesAcceptedwith a capital letter.sudo grep 'accepted' /var/log/secure sudo grep -i 'accepted' /var/log/secure