grep: Searching Text with Regular Expressions

grep (Global Regular Expression Print) is a powerful command-line utility for searching plain-text data sets for lines that match a regular expression. It’s an indispensable tool for system administrators, developers, and anyone working with text files to quickly find specific information, filter logs, or analyze data.

1. Basic Searching

Case-Insensitive Search with Extended Regular Expressions

This command searches for lines containing “Network Admin” or “BFHQNASA01”, ignoring case, and using extended regular expressions.

grep -Ei "Network Admin|BFHQNASA01" <filename>
# Example: Search in a log file
grep -Ei "error|fail" /var/log/syslog
  • -E: Interprets PATTERN as an extended regular expression (ERE). This allows for features like | (OR operator) without escaping.
  • -i: Ignores case distinctions in both the PATTERN and input files.

2. Recursive Search Through Files and Directories

To search for a pattern within multiple files, including those in subdirectories.

grep -rin "WALinux" DT/logs/
# Example: Find "ERROR" in all .log files in the current directory and subdirectories
grep -rin "ERROR" ./*.log
  • -r: (recursive) Recursively searches through files in directories.
  • -n: (line-number) Displays the line number of each match.
  • -H: (with-filename) Prints the filename for each match. (Implicit when searching multiple files or recursively).

3. Extracting Only the Matches (-o)

The -o option (only-matching) prints only the matched (non-empty) parts of a matching line, with each such part on a separate output line. This is useful for extracting specific data.

grep -oE '([0-9]{1,3}\.){3}[0-9]{1,3}' <filename>
# Example: Extract all IPv4 addresses from a text file
grep -oE '([0-9]{1,3}\.){3}[0-9]{1,3}' access.log
  • ([0-9]{1,3}\.){3}[0-9]{1,3}: A regular expression to match IPv4 addresses.

4. Displaying Context Around Matches

Sometimes, seeing the lines before and after a match provides valuable context.

  • -C <num>: (context) Prints num lines of context around each match.
  • -B <num>: (before-context) Prints num lines of leading context before each match.
  • -A <num>: (after-context) Prints num lines of trailing context after each match.
# Show 5 lines of context around lines containing "ERROR"
grep -C 5 "ERROR" /var/log/syslog

5. Other Useful grep Options

  • -v: (invert-match) Selects non-matching lines (i.e., lines that do NOT contain the pattern).
  • -c: (count) Suppresses normal output; instead, prints a count of matching lines for each file.
  • -L: (files-without-match) Prints only the names of files that do NOT contain matches.
  • -q: (quiet) Suppress all output. Exits immediately with 0 status if any match is found, 1 otherwise.

Note: When working with large files or directories, grep can be resource-intensive. Consider piping its output to head or less if you’re only interested in a small portion of the results, or using rg (ripgrep) for better performance on large codebases.