The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Find matching linesgrep 'ERROR' app.logView examples
Match literal textgrep -F 'user[id]' app.logView examples
Ignore letter casegrep -i 'warning' app.logView examples
Show line numbersgrep -n 'timeout' app.logView examples
Exclude matching linesgrep -v '^#' settings.confView examples
Use extended patternsgrep -E 'ERROR|WARN' app.logView examples
Replace the first matchsed 's/http:/https:/' links.txtView examples
Replace every matchsed 's/[[:space:]]\{1,\}/ /g' notes.txtView examples
Remove matching linessed '/^[[:space:]]*$/d' notes.txtView examples
Print selected fieldsawk -F',' '{print $1, $3}' records.csvView examples
Filter numeric fieldsawk -F',' '$3 >= 80 {print $1, $3}' scores.csvView examples
Sum a columnawk -F',' 'NR > 1 {sum += $3} END {print sum}' sales.csvView examples
Extract delimited fieldscut -d: -f1,7 /etc/passwdView examples
Sort textsort names.txtView examples
Sort numericallysort -t, -k2,2n scores.csvView examples
Count repeated linessort statuses.txt | uniq -cView examples
Convert letter casetr '[:lower:]' '[:upper:]' < names.txtView examples
Delete characterstr -d '\r' < windows.txtView examples
Count lineswc -l < app.logView examples
Summarize a fieldawk -F',' 'NR > 1 {print $2}' requests.csv | sort | uniq -c | sort -nrView examples

Unix text tools are strongest when each stage performs one visible transformation. Start with read-only output, quote patterns and filenames, choose delimiters deliberately, and validate intermediate results before redirecting them into a file.

Step by step

Detailed examples

01

Select and exclude lines with grep

grep interprets its pattern as a basic regular expression unless -E selects extended syntax or -F requests literal matching. Quote patterns so the shell does not expand metacharacters first. Exit status 0 means a match, 1 means no match, and values above 1 indicate an error—an important distinction in scripts.

Search a small log several ways
printf '%s\n' 'INFO started' 'WARN slow response' 'ERROR user[id] timeout' > app.log
grep -E 'ERROR|WARN' app.log
grep -Fn 'user[id]' app.log
grep -iv 'info' app.log
Output
WARN slow response
ERROR user[id] timeout
3:ERROR user[id] timeout
WARN slow response
ERROR user[id] timeout
Ignore comments without changing the file
printf '%s\n' '# generated' 'port=8080' 'host=localhost' > settings.conf
grep -v '^#' settings.conf
Output
port=8080
host=localhost
Back to quick reference ↑
02

Transform a stream with sed

sed reads input and writes transformed text to standard output, which makes its default behavior safe for inspection. The s command replaces the first match per line unless the g flag is present; d suppresses selected lines. GNU sed's -i changes files in place, so prefer reviewed output or an explicit backup when editing valuable data.

Replace URLs and omit blank lines
printf '%s\n' 'http://one.test http://two.test' '' 'http://three.test' > links.txt
sed -e 's#http:#https:#g' -e '/^[[:space:]]*$/d' links.txt
Output
https://one.test https://two.test
https://three.test
Normalize repeated horizontal whitespace
printf '%s\n' 'alpha    beta' 'gamma  delta' | sed 's/[[:space:]]\{1,\}/ /g'
Output
alpha beta
gamma delta
Back to quick reference ↑
03

Process records and fields with awk

awk evaluates pattern-action rules for every record. -F sets the input field separator, $1 through $NF address fields, NR counts records, and END runs after all input. Simple delimiter splitting works for uncomplicated records; quoted CSV containing embedded commas needs a CSV-aware parser rather than -F,.

Filter and total simple comma-delimited data
printf '%s\n' 'name,team,score' 'Ada,red,92' 'Grace,blue,78' 'Linus,red,85' > scores.csv
awk -F',' 'NR > 1 && $3 >= 80 {print $1, $3; sum += $3} END {print "total", sum}' scores.csv
Output
Ada 92
Linus 85
total 177
Back to quick reference ↑
04

Extract uncomplicated delimited columns with cut

cut selects character positions or delimiter-separated fields without interpreting a schema. Its delimiter is one character, and it does not understand quoting or escaped delimiters. It is ideal for stable formats such as /etc/passwd; use awk or a format-aware tool when selection depends on values or records are more complex.

Show user names and login shells
printf '%s\n' 'ada:x:1001:1001::/home/ada:/bin/bash' 'build:x:1002:1002::/srv/build:/usr/sbin/nologin' | cut -d: -f1,7
Output
ada:/bin/bash
build:/usr/sbin/nologin
Back to quick reference ↑
05

Sort before grouping repeated lines

sort orders lines, with -n comparing numeric keys and -k selecting key ranges. uniq only combines adjacent equal lines, so unsorted data usually needs sort first. Locale affects text order; set LC_ALL=C only when bytewise, reproducible ordering is the intended contract. wc -l counts newline characters, which can differ from a human notion of lines when the final record lacks a newline.

Build a frequency table
printf '%s\n' ok error ok pending error ok | sort | uniq -c | sort -nr
Output
      3 ok
      2 error
      1 pending
Sort a numeric field
printf '%s\n' 'Ada,9' 'Grace,12' 'Linus,3' | sort -t, -k2,2n
Output
Linus,3
Ada,9
Grace,12
Back to quick reference ↑
06

Translate or delete character sets with tr

tr maps characters from one set to another or removes them with -d. It reads standard input rather than filenames. Quoted POSIX character classes such as [:lower:] express intent more clearly than ASCII ranges, while deleting carriage returns is useful for CRLF input only after confirming that those bytes are unwanted.

Uppercase text and remove carriage returns
printf 'Ada\r\nGrace\r\n' | tr -d '\r' | tr '[:lower:]' '[:upper:]'
Output
ADA
GRACE
Back to quick reference ↑
07

Compose small stages and inspect each boundary

A pipeline connects one command's standard output to the next command's standard input. Build it incrementally so field selection, normalization, and ordering can be verified independently. In production shell scripts, enable an appropriate pipeline failure policy and write to a temporary output before replacing valuable files.

Count HTTP methods from simple request records
printf '%s\n' 'time,method,path' '1,GET,/' '2,POST,/login' '3,GET,/docs' '4,GET,/' > requests.csv
awk -F',' 'NR > 1 {print $2}' requests.csv | sort | uniq -c | sort -nr
Output
      3 GET
      1 POST
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. GNU ProjectGNU grep Manualgnu.org
  2. GNU ProjectGNU sed Manualgnu.org
  3. GNU ProjectGNU Awk User's Guidegnu.org
  4. GNU ProjectGNU Coreutils Manualgnu.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback