Skip to content
abdallahmekky

CHEAT SHEET

grep, sed & awk cheat sheet

Search, filter and rewrite text from the terminal. The four tools every sysadmin uses daily.

All cheat sheets

grep

grep "text" file               # lines that contain textgrep -i "text" file            # ignore casegrep -n "text" file            # show line numbersgrep -v "text" file            # lines that do NOT matchgrep -c "text" file            # count the matching linesgrep -r "text" /etc            # search a folder recursivelygrep -rl "text" /etc           # only list the file namesgrep -w "root" file            # whole word onlygrep -E "foo|bar" file         # extended regex (OR)grep -A2 -B2 "text" file       # 2 lines after and before each matchgrep -o "[0-9]\+" file         # print only the matching part

find

find /etc -name "*.conf"                  # by namefind / -iname "readme*"                   # by name, ignore casefind /var -type f -size +50M              # files bigger than 50 MBfind /home -user alice                    # owned by a userfind / -perm -4000 2>/dev/null            # setuid files, hiding permission errorsfind . -mtime -1                          # modified in the last dayfind . -type f -name "*.tmp" -delete      # delete the matchesfind . -name "*.log" -exec gzip {} \;     # run a command on each matchfind . -name "*.log" -print0 | xargs -0 ls -l    # safe with spaces in names

sed

sed 's/old/new/' file                # replace the first match on each linesed 's/old/new/g' file               # replace every matchsed -i 's/old/new/g' file            # edit the file in placesed -i.bak 's/old/new/g' file        # in place, keeping a .bak backupsed -n '5,10p' file                  # print only lines 5 to 10sed '/^#/d' file                     # delete comment linessed '/^$/d' file                     # delete empty linessed '3d' file                        # delete line 3sed 's/^/    /' file                  # indent every line by four spacessed -E 's/([0-9]+)/<\1>/g' file      # extended regex with a group

awk

awk '{print $1}' file                        # first columnawk -F: '{print $1, $3}' /etc/passwd         # a custom field separatorawk -F: '$3 >= 1000 {print $1}' /etc/passwd  # users with UID 1000 or moreawk 'NR==5' file                             # line number 5awk 'END {print NR}' file                    # number of linesawk '{sum += $1} END {print sum}' file       # add up a columnawk '/error/ {c++} END {print c}' log        # count matching linesawk '{print NF}' file                        # number of fields on each line

sort, cut, tr and friends

cut -d: -f1,3 /etc/passwd           # fields 1 and 3, ":" delimitedsort file                           # sort linessort -n -r -u file                  # numeric, reverse, uniquesort file | uniq -c | sort -nr      # count duplicates, most common firsttr 'a-z' 'A-Z' < file               # uppercasetr -d '\r' < file                   # remove carriage returnswc -l file                          # count lines (-w words, -c bytes)head -n 5 file                      # first 5 linestail -n 5 file                      # last 5 linestail -f /var/log/messages           # follow a logdiff -u a b                         # compare two filescolumn -t file                      # align columnscmd | tee out.txt                   # show the output and save it

Regex quick reference

PatternMatches
.Any single character
*Zero or more of the previous item
+ ?One or more, zero or one (extended regex, grep -E)
^ $Start and end of the line
[abc] [^abc]One of these characters, none of these characters
[0-9] [a-z]A range
( ) |Group, alternation (extended regex)
\bWord boundary (GNU)

More cheat sheets

Questions

How do I search for text in all files under a folder?

Use grep -r "text" /path. Add -n for line numbers, -i to ignore case and -l to list only the file names.

How do I replace text in a file with sed?

Use sed -i 's/old/new/g' file. The g replaces every match on each line and -i edits the file in place. Use -i.bak to keep a backup.

How do I print one column with awk?

Use awk '{print $1}' file for the first whitespace-separated column. Use -F: to change the separator, for example awk -F: '{print $1}' /etc/passwd.

How do I find files bigger than 50 MB?

Use find /var -type f -size +50M. Add 2>/dev/null to hide permission errors.