This beginner course builds a practical command-line workflow for reading Linux text logs and extracting useful evidence. Through five guided labs, you will locate common log files, follow new events, search and count records, select structured fields with awk, and transform text streams with sed.
The final investigation challenge combines those tools with evidence handling: copy a prepared authentication log, identify the repeated source IP, extract the first and last matching timestamps, and compile a short incident report.
What You Will Learn
- Explore
/var/logand inspect recent entries fromsyslogandauth.log - Follow appended authentication events in real time with
tail -f - Filter failed-login entries with
grepand count matches through a pipeline withwc -l - Narrow log results by date or other literal text patterns
- Extract selected whitespace-delimited fields from system and access logs with
awk - Substitute text, omit line ranges, and mask sample usernames with
sed - Preserve original evidence by copying a log before investigation
- Identify an attacker IP, derive first and last event times, and assemble an incident summary
Who This Course Is For
This course is for Linux beginners, support technicians, and aspiring operations or security practitioners who want a focused introduction to text-log inspection and shell-based evidence extraction.
Prerequisites: Basic terminal navigation, file viewing, pipes, output redirection, and sudo; no prior awk or sed experience is required.
Learning environment: A provided Ubuntu-based LabEx terminal with prepared traditional text logs, two-terminal support for live monitoring, sample text files, and a synthetic authentication incident.
Frequently Asked Questions
How is the course structured?
Five labs provide guided practice. The sixth item is an incident challenge where you analyze a copied auth.log, save the attacker IP and timeline, and create a short report with less guidance.
Does this course cover journalctl or log rotation?
No. It focuses on traditional files under /var/log and general text-processing tools. systemd journal queries, logrotate configuration, retention, and compressed archives are outside this course.
Do the sed exercises modify the original files?
No. The demonstrated commands omit -i, so substitutions, line deletion, and masking are printed as transformed output while the source files remain unchanged.
Is the security incident based on real production data?
No. The lab provides a synthetic authentication log with repeated failures from 203.0.113.42. You preserve a copy, extract both boundary timestamps, and include at least the IP and start time in incident_report.txt.





