Grep in Linux: Find the Right Lines Without Searching Blindly
When a log file is thousands of lines long, opening it and scrolling usually isn’t the fastest way to find what matters. grep searches file contents for lines matching a pattern—and a few options make the difference between a useful result and a noisy one. Start with a focused search grep 'connection refused' app.log This prints each line in app.log containing the case-sensitive phrase. Add -n to…
Searching for specific lines in lengthy log files can be inefficient. The Linux utility 'grep' allows searching file contents for matching patterns. A basic search can be performed with `grep "connection refused" app.log`, which displays each line in 'app.log' containing the exact phrase "connection refused". To include line numbers in the output, use `grep -n "connection refused" app.log`.
The search pattern should be quoted when it contains spaces or punctuation, to prevent the shell from interpreting it. Grep searches file contents, not filenames. A wildcard like `*.log` expands to a list of filenames in the shell before being passed to grep.
The pattern to search for determines the search results. By default, grep interprets the pattern as a basic regular expression, which may result in unexpected matches due to special characters. To match the literal text 'v1.2', use the `-F` option: `grep -F "v1.2" app.log`. For searching with regular expression alternatives, such as 'warning or error', use `-E`: `grep -E "warning|error" app.log`.
To match whole words only, use `-w`: `grep -w "cat" notes.txt`. Starting with the beginning of a line can be achieved using the `^` anchor: `grep ^PermitRootLogin sshd_config`.
Context around matching lines can provide additional information. Displaying two lines after a match can be done with `grep -C 2 failed app.log`. Other options include counting matching lines with `-c`, ignoring lines that do not match with `-v`, printing filenames with matches using `-l`, and extracting matching parts with `-o`.
Grep can be used to search within directories by running `grep -r -n "TODO" src/`, which recursively searches for 'TODO' within files in the 'src' directory. GNU grep can search for files matching a pattern using `--include = *.conf` and the `-r` option.
When searching through multiple files or directories, it is helpful to narrow the scope first. Use the `find` command to locate files by name or type, then pipe the output to grep for searching their contents. For example, `find ./config -type f -name *.conf -exec grep -nH "server_name" {} +` finds all `.conf` files in the './config' directory and searches them for 'server_name'.
Grep can also filter the output of other commands using pipelines. For example, `ps aux | grep nginx` searches the output of the 'ps' command for 'nginx'. To avoid matching the grep process itself, use `ps aux | grep [n]ginx`. If grep returns no output, it may indicate no matches rather than an error. Check the path, spelling, capitalization, and file permissions.
Use `-F` for literal text, `-i` for case-insensitive matching, and `-e` to explicitly mark a pattern when it starts with a hyphen.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.