Q: A log file consists of rows like: `ERROR 2023-10-01 User bob failed login`. Using basic Linux text processing, how would you print only the names (like 'bob') of the users who failed?
I would use awk.
#Linux #Linux / SRE — Scenario-Based Interview Questions #L1 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""In an interview, I explain my systematic Linux troubleshooting methodology using Brendan Gregg's USE method. The interviewer is testing: `awk` usage, stream manipulation.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Production Solution & Architecture
I would use awk. By default, awk splits strings by whitespace into numbered variables. The command would be: cat app.log | grep "failed login" | awk '{print $4}'. Since "bob" is the 4th word separated by spaces (ERROR is $1, date is $2, User is $3), it cleanly extracts just the username.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: I would use awk.."
⚡ 60-Second Elevator Pitch Talking Points
- Immediate Triage: I would use awk.
- Run targeted verification commands before modifying configuration.
- Automate permanent guardrails (CI check, alerts, IaC policy) to prevent recurrence.
Advertisement