During an incident investigation, a security analyst discovers the web server is generating an unusually high volume of logs. The analyst observes the following response codes:
• 20% of the logs are 403
• 20% of the logs are 404
• 50% of the logs are 200
• 10% of the logs are other codes
The server generates 2MB of logs on a daily basis, and the current day log is over 200MB. Which of the following commands should the analyst use to identify the source of the activity?
Dutch012
Highly Voted 1 year, 10 months agogrelaman
Most Recent 1 year, 7 months agogrelaman
1 year, 7 months agoBig_Dre
1 year, 7 months agoDutch012
1 year, 10 months agoCyberCEH
1 year, 11 months agoreidsel
1 year, 11 months agoHershey2025
1 year, 12 months agokiduuu
2 years ago