Exercise

Searching Log Files with grep Exercise

Task

In this hands-on exercise, investigate the SSH service with grep by searching authentication logs, checking service status, and refining command output.

Target host
servera
Privileges
sudo access to read /var/log/secure and inspect sshd
  1. Find matching log entries

    Connect to servera and find SSH events in the root-only authentication log.

    ssh student@servera
    sudo grep 'sshd' /var/log/secure

    Limit the results to successful authentication.

    sudo grep 'Accepted' /var/log/secure
  2. Show context around matches

    Check the SSH service status, then use -B2 and -A3 to keep the service identity, load state, and details around the active state.

    systemctl status sshd | grep -B2 -A3 'Active:'
  3. Refine results with grep options

    Confirm that SSH processes are running. Notice that grep also finds its own process.

    ps ax | grep 'sshd'

    Pipe it into a second grep with -v, which prints every line that does not match.

    ps ax | grep 'sshd' | grep -v 'grep'

    Ask sshd for its effective configuration, then give -e once for each setting to display.

    sudo sshd -T | grep -e '^port ' -e '^permitrootlogin '

    Run the search twice and compare the results. Without -i, the pattern misses every line that uses Accepted with a capital letter.

    sudo grep 'accepted' /var/log/secure
    sudo grep -i 'accepted' /var/log/secure