Skip to main content

Command Palette

Search for a command to run...

Advanced Linux Commands:

awk, sed, cut, sort & uniq in Action

Published
•9 min read•View as Markdown
P

As a associate system administrator I worked on Redhat Linux servers, including user management, permissions, services, and performance monitoring Automated routine administrative tasks using Bash scripting and cron jobs, reducing manual effort by ~30% I am aws certified sysops administrator and Google Certified Cloud Engineer. Determined to transition my career into cloud architect /Cloud Support role

If you work with Linux servers on AWS, the command line isn’t optional — it’s your superpower. Whether you’re debugging a web app on an EC2 instance, parsing logs from NGINX, or analyzing user accounts, mastering text-processing tools like awk, sed, cut, sort, and uniq will save you hours.

Let’s break down these commands with practical AWS/Linux admin examples.


🧙 awk – Column Extraction Magic

awk is a powerful pattern scanning and processing tool. It shines when working with structured text like logs or system files.

1️⃣ Extract IP Addresses from NGINX Logs

awk '{print $1}' /var/log/nginx/access.log

This prints the first column, typically the client IP address.

Example NGINX log format:

192.168.1.10 - - [16/Feb/2026] "GET /index.html" 200 1024

Output:

💡 Useful on AWS EC2 instances to identify traffic sources.


2️⃣ Extract Usernames from /etc/passwd

awk -F: '{print $1}' /etc/passwd
  • -F: sets : as the delimiter.

  • Prints system usernames.

Sample /etc/passwd entry:

ec2-user:x:1000:1000::/home/ec2-user:/bin/bash

Output:

ec2-user

Great for auditing users on Linux servers.


3️⃣ Find IPs That Caused 404 Errors

awk '$9 == 404 {print $1}' /var/log/nginx/access.log
  • $9 refers to the HTTP status code field.

  • Filters only 404 errors.

  • Prints the IP responsible.

Perfect for detecting broken links or suspicious scanning activity on AWS-hosted apps.


✂ sed – Stream Editing Made Simple

sed edits text in a stream without opening a text editor.

Replace Text Globally:

🧩 Complex Example:

Patch an NGINX server Block Automatically

You need to update every NGINX virtual host so that:

  • HTTP requests get redirected to HTTPS

  • AND you add a security header inside the correct server {} block

This is a typical “fleet patch” you might run via SSH / SSM / user-data.

Input (/etc/nginx/conf.d/site.conf)

server {
    listen 80;
    server_name example.com;
    root /usr/share/nginx/html;
}

Goal (after patch)

  • Add redirect rule

  • Add X-Frame-Options header

  • Only within the server {} block that listens on 80


✅ One-liner sed solution :

sed -i '
/server\s*{/,
/}/{
  /listen\s\+80;/a\
  return 301 https://$host$request_uri;
  /server_name/a\
  add_header X-Frame-Options "SAMEORIGIN" always;
}
' /etc/nginx/conf.d/site.conf

What’s happening here?

  • /server\s*{/ , /}/
    Selects a range from server { to the next closing }.

  • Inside that range:

    • When it matches listen 80;, it appends the redirect line right after it (a\)

    • When it matches server_name, it appends a security header right after it

This is “complex sed” because it:
✅ Works on blocks, not single lines
✅ Inserts content in the correct context
✅ Avoids manual editing errors
✅ Scales across many files


Run across all vhosts (typical AWS pattern)

for f in /etc/nginx/conf.d/*.conf; do
  sed -i '
  /server\s*{/,
  /}/{
    /listen\s\+80;/a\
    return 301 https://$host$request_uri;
    /server_name/a\
    add_header X-Frame-Options "SAMEORIGIN" always;
  }' "$f"
done

Validate before reload (best practice)

nginx -t && systemctl reload nginx

Bonus Tip: Safe mode (backup first)

sed -i.bak '...' /etc/nginx/conf.d/site.conf

This keeps a backup file like site.conf.bak—great for production changes.

sed 's/old/new/g' config.txt
  • Replaces all occurrences of old with new.

  • Useful when updating configuration files across EC2 instances.


Print Specific Line Range

sed -n '10,20p' large-file.txt
  • Prints lines 10–20.

  • Helpful when debugging massive log files.

Instead of opening the entire file, you surgically inspect just what you need.


🔪 cut – Simple Field Extraction

When you don’t need full awk power, cut is lightweight and fast.

Extract First Field Using Colon

cut -d: -f1 /etc/passwd

Same output as awk example — but simpler syntax.


Extract Specific Character Range

cut -c1-10 filename

Prints characters 1–10 of each line.

Great for formatting reports or extracting fixed-width data.


📊 sort & uniq – Log Analysis Combo

These commands are powerful together.

Count and Sort Unique IPs

sort /var/log/ips.txt | uniq -c | sort -nr

What happens here:

  1. sort → Groups identical IPs together.

  2. uniq -c → Counts occurrences.

  3. sort -nr → Sorts numerically in reverse order (highest first).

Output example:

120 192.168.1.10
 85 10.0.0.5
 12 172.31.20.4

🔥 This quickly identifies top traffic sources — extremely useful for:

  • Detecting DDoS patterns

  • Identifying bot traffic

  • Monitoring suspicious activity


🚀 Real AWS Use Case: EC2 Log Investigation

Imagine your application running on an AWS EC2 instance is slowing down.

You could run:

awk '{print $1}' /var/log/nginx/access.log | sort | uniq -c | sort -nr | head

Boom 💥 — instant visibility into which IP is hammering your server.

No third-party tool required.


⚡ Why These Commands Matter in AWS Environments

On AWS:

  • You manage EC2 instances.

  • You monitor logs in /var/log.

  • You troubleshoot NGINX, Apache, or application logs.

  • You analyze user accounts and permissions.

  • You automate tasks via shell scripts.

These tools are:

✔ Lightweight
✔ Installed by default
✔ Extremely fast
✔ Script-friendly
✔ Production-proven


🏁 Final Thoughts

If you're working as a Linux Admin, Cloud Engineer, or DevOps professional, mastering:

  • awk for pattern filtering

  • sed for stream editing

  • cut for quick extraction

  • sort & uniq for analysis

is non-negotiable.

In AWS environments, speed of troubleshooting equals uptime — and uptime equals reliability.

Command-line mastery isn’t old-school. It’s elite-level efficiency.

If you want, I can convert this into a Hashnode-ready blog version with SEO keywords and formatting optimized for LinkedIn as well.

Extend above article

Love this topic. These commands look “basic” on the surface… but in real AWS production environments, they are surgical tools. Let’s go deeper and turn this into a proper Linux + AWS admin playbook.


Advanced Linux Text Processing for AWS Engineers

When you’re managing EC2 instances, debugging NGINX, rotating logs, or analyzing security events — GUI dashboards won’t save you. The shell will.

Let’s extend the earlier examples into real-world, production-ready scenarios.


🔍 awk – Beyond Basic Extraction

awk isn’t just for printing columns. It can filter, calculate, aggregate, and even generate reports.


1️⃣ Top 10 IPs Hitting Your EC2 Server

awk '{print $1}' /var/log/nginx/access.log | \
sort | uniq -c | sort -nr | head -10

This command pipeline:

  • Extracts IPs

  • Counts occurrences

  • Sorts by highest traffic

  • Displays top offenders

🔥 Real AWS Use Case:
If your EC2 CPU suddenly spikes, this helps detect:

  • Bot traffic

  • Brute force attempts

  • Load testing issues

  • DDoS-style bursts


2️⃣ Count Total 404 Errors

awk '$9 == 404 {count++} END {print count}' /var/log/nginx/access.log

This gives a clean numeric result.

Perfect for:

  • Health monitoring

  • CI/CD validation

  • Log-based alerting

You can even integrate this inside a cron job and push metrics to CloudWatch.


3️⃣ Calculate Total Bandwidth Served

Assuming $10 represents response size:

awk '{sum += $10} END {print sum/1024/1024 " MB"}' /var/log/nginx/access.log

Now you can estimate:

  • Outbound bandwidth usage

  • Data transfer costs

  • CDN optimization opportunities

That’s direct cost-awareness from raw logs.


✏ sed – Configuration Automation Power

On AWS, configuration consistency is everything.


4️⃣ Update NGINX Config Across Multiple EC2 Instances

sed -i 's/worker_processes 1/worker_processes auto/' /etc/nginx/nginx.conf

-i edits the file in place.

Common AWS tasks:

  • Change backend IPs

  • Replace domain names

  • Update environment variables

  • Fix misconfigured ports


5️⃣ Comment Out a Line Automatically

sed -i 's/^server/#server/' config.txt

Useful when disabling settings without deleting them.

This is extremely helpful during blue-green deployments.


🔪 cut – Clean & Fast Extraction

When speed matters and structure is simple, cut wins.


6️⃣ List Only Home Directories of Users

cut -d: -f6 /etc/passwd

Output:

/root
/home/ec2-user
/home/admin

Quick visibility during:

  • User audits

  • Security investigations

  • Permission debugging


📊 sort & uniq – Security Analysis Engine

These two commands together can expose patterns instantly.


7️⃣ Detect Failed SSH Login Attempts

If logs exist in:

/var/log/secure

You can extract failed attempts:

grep "Failed password" /var/log/secure | \
awk '{print $11}' | sort | uniq -c | sort -nr

Boom. Now you know:

  • Which IP is brute-forcing

  • How many attempts were made

In AWS, you can use this to decide whether to:

  • Block IP via Security Group

  • Add fail2ban

  • Enable AWS WAF rules


🧠 Combining Everything: Real Incident Response Scenario

Imagine:

Your AWS-hosted website is slow.

Here’s how a Linux admin investigates:


Step 1 – Check Top IPs

awk '{print $1}' /var/log/nginx/access.log | \
sort | uniq -c | sort -nr | head

Step 2 – Check Error Rate

awk '$9 >= 500 {print $0}' /var/log/nginx/access.log | wc -l

Step 3 – Check CPU Usage

top

Step 4 – Identify Large Responses

awk '$10 > 1000000 {print $7, $10}' /var/log/nginx/access.log

This could reveal:

  • Large file downloads

  • Misconfigured endpoints

  • Data leakage risks

All without external monitoring tools.


🛠 Automating with Bash Script on AWS

Here’s a simple daily report script:

#!/bin/bash

LOG="/var/log/nginx/access.log"

echo "Top 5 IPs:"
awk '{print $1}' $LOG | sort | uniq -c | sort -nr | head -5

echo "Total 404 errors:"
awk '$9 == 404 {count++} END {print count}' $LOG

Schedule it:

crontab -e

Add:

0 0 * * * /home/ec2-user/report.sh > /home/ec2-user/daily_report.txt

Now you have automated observability — without expensive tools.


⚙ Performance Tips for Large Log Files

When dealing with multi-GB log files on production EC2:

✔ Use less instead of cat
✔ Use head and tail
✔ Use zgrep for compressed logs
✔ Use awk filtering before sorting (reduces memory usage)

Example:

awk '$9 == 404' access.log | sort | uniq -c

Filtering first reduces workload dramatically.


☁ Why This Matters in AWS

Cloud doesn’t remove Linux fundamentals.

Even with:

  • CloudWatch

  • AWS WAF

  • Elastic Load Balancer

  • GuardDuty

  • Athena log queries

You will still SSH into EC2 during incidents.

And when you do — these commands are your fastest weapons.


🚀 Final Takeaway

Mastering:

  • awk for smart parsing

  • sed for config automation

  • cut for quick slicing

  • sort + uniq for traffic analysis

makes you:

✔ Faster in debugging
✔ Stronger in security analysis
✔ More cost-aware
✔ More production-ready

The cloud rewards engineers who understand what’s happening under the hood.

And under the hood… it’s still Linux.