Linux Commands Chapter 2: Text Searching with Grep & Master Shell Operators
Linux Administration aur Cybersecurity (SOC Analysis, Incident Response) me text files, config files, aur log files se kaam ki information nikalna sabse zaroori skill hai. Is guide me hum seekhenge ki grep command ki madad se kisi bhi file se targeted data kaise dhoondha jata hai aur Shell Operators ka use karke terminal commands ko kaise automate aur redirect kiya jata hai.
Part 1: Advanced Text Searching Using grep
grep (Global Regular Expression Print) ek powerful CLI tool hai jo kisi file ke andar specific text, pattern, ya string ko fast scan aur filter karta hai.
1. Simple Log File Searching
Imagine kariye aapke paas ek web server ka access.log file hai jisme 244 entries hain. Manual check karne ke bajaye grep ki madad se aap specific IP address ya path ki activity ek second me nikal sakte hain.
File me total lines count karna:
Bash
wc -l access.log
# Output: 244 access.log
(Yahan wc -l ne file ki kul lines count karke bata di.)
Specific IP Address ko filter karna: Agar aapko dekhna hai ki IP 81.143.211.90 ne server par kya-kya access kiya hai, toh ye command chalayein:
Bash
grep "81.143.211.90" access.log
Output:
Plaintext
81.143.211.90 – – [25/Mar/2021:11:17 +0000] "GET / HTTP/1.1" 200 417 "-" "Mozilla/5.0 (Linux; Android 7.0; Moto G(4))"
grep ne poore file me se sirf wahi log entry show ki jisme ye specific IP address maujood tha.
2. Recursive Search Across Multiple Files (-R)
Jab aapko ye nahi pata ho ki target string kis exact file me hai, toh aap poore directory aur uske subfolders me ek sath search kar sakte hain. Iske liye -R (Recursive) flag ka use hota hai.
Example: /etc/ directory ke andar check karna ki kis file me PRETTY_NAME likha hai:
Bash
grep -R "PRETTY_NAME" /etc/
Output:
Plaintext
grep: /etc/sudoers: Permission denied
/etc/os-release:PRETTY_NAME="Ubuntu"
grep ne poori /etc/ directory aur sub-folders me scan karke bataya ki OS ki detail /etc/os-release file me hai.
Part 2: Essential Linux Shell Operators
Shell operators terminal par kaam karne ki speed aur efficiency ko kayi guna badha dete hain. Ye command execution, redirection, aur background processes ko control karte hain.
| Symbol / Operator | Name | Short Description |
|---|---|---|
& | Background Execution | Command ko background me run karta hai. |
&& | Logical AND | Pehla command success hone par hi doosra chalata hai. |
> | Redirection (Overwrite) | Output ko file me save karta hai (purana text mita kar). |
>> | Redirection (Append) | Output ko file ke end me add karta hai (bina mitaaye). |
1. Background Execution Operator (&)
Jab aap koi bada task chalate hain (jaise large file copy karna ya network scan karna), toh terminal tab tak lock ho jata hai. Command ke aage & lagane se wo task background me chala jata hai aur aapka terminal immediate naye task ke liye free ho jata hai.
Bash
cp huge_database.db /backup/ &
2. Sequential Conditional Operator (&&)
Iska use tab hota hai jab aap ek line me multiple commands chalana chahte hain, par aap chahte hain ki Command 2 tabhi chale jab Command 1 successfully execute ho jaye.
Bash
sudo apt update && sudo apt upgrade -y
(Isme apt upgrade tabhi chalega jab apt update bina kisi error ke complete hoga.)
3. Output Redirection Operator (>)
Ye operator kisi command ke output ko screen par print karne ke bajaye ek file me save kar deta hai.
Important Note: Agar file pehle se maujood hai, toh
>operator uska purana content delete (overwrite) kar dega.
Bash
echo "hey" > welcome.txt
cat welcome.txt
# Output: hey
4. Output Append Operator (>>)
Ye > operator ki tarah hi kaam karta hai, lekin ye file ke purane data ko delete nahi karta. Ye naye output ko file ke aakhiri me (end me) add kar deta hai.
Bash
echo "hello" >> welcome.txt
cat welcome.txt
# Output:
# hey
# hello
(Aap dekh sakte hain ki hey delete nahi hua, balki hello uske neeche add ho gaya.)
Summary Cheat-Sheet
- Search specific text in a file:
grep "pattern" filename - Search text in all files/subfolders:
grep -R "pattern" /path/to/dir/ - Run command in background:
command & - Run second command only on success:
cmd1 && cmd2 - Save output to file (Overwrite):
command > file.txt - Add output to file (Append):
command >> file.txt

