// hands-on lab
Log detective
~14 min
Answer incident questions with pipelines.
The shell has realistic logs seeded in /var/log. Investigate:
1. `grep ERROR /var/log/syslog` — any errors on this box? 2. `grep -r flooding /var/log` — find the SYN flood warning 3. `cat /var/log/nginx.log | grep 403` — who's being denied? 4. `awk '{print $1}' /var/log/nginx.log | sort | uniq` — distinct client IPs 5. `journalctl -u nginx` — the service's own journal 6. Save evidence: `grep 403 /var/log/nginx.log > ~/evidence.txt && cat ~/evidence.txt`
// checklist
Sign in to save checklist progress.
Click Start sandbox for an in-browser Linux environment.
No Docker on the server — the sandbox runs in your browser (or an embedded lab host).