Q: You ssh to a Linux box to check some logs manually via `less /var/log/syslog`. There are millions of lines. How do you find lines containing "error" and view the lines immediately around them without leaving `less`?
Inside less I would:
#Observability #Observability #L1 #Monitoring #Prometheus #SRE
🎙️ Candidate Opening & Architectural Context
""Logs tell you what happened, metrics tell you where to look, and distributed traces pinpoint the exact slow component. The interviewer is testing: Command line skills for quick observability, `less` shortcuts.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Inside less I would:
- Press
/and typeerrorand press Enter to search forward. - Use
nto jump to the next match, andNto jump to previous match. - The lines immediately around the match are visible because
lessdisplays the page containing the match.
2️⃣
Remediation & Permanent Safeguards
If I wanted to exit less and output this to another file, I'd use grep -C 5 "error" /var/log/syslog > errors.txt (where -C 5 gives 5 lines of context before and after the match).
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Press / and type error and press Enter to search forward.."
⚡ 60-Second Elevator Pitch Talking Points
- Press / and type error and press Enter to search forward.
- Use n to jump to the next match, and N to jump to previous match.
- The lines immediately around the match are visible because less displays the page containing the ...
Advertisement