The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Find matching lines | grep 'ERROR' app.log | View examples |
| Match literal text | grep -F 'user[id]' app.log | View examples |
| Ignore letter case | grep -i 'warning' app.log | View examples |
| Show line numbers | grep -n 'timeout' app.log | View examples |
| Exclude matching lines | grep -v '^#' settings.conf | View examples |
| Use extended patterns | grep -E 'ERROR|WARN' app.log | View examples |
| Replace the first match | sed 's/http:/https:/' links.txt | View examples |
| Replace every match | sed 's/[[:space:]]\{1,\}/ /g' notes.txt | View examples |
| Remove matching lines | sed '/^[[:space:]]*$/d' notes.txt | View examples |
| Print selected fields | awk -F',' '{print $1, $3}' records.csv | View examples |
| Filter numeric fields | awk -F',' '$3 >= 80 {print $1, $3}' scores.csv | View examples |
| Sum a column | awk -F',' 'NR > 1 {sum += $3} END {print sum}' sales.csv | View examples |
| Extract delimited fields | cut -d: -f1,7 /etc/passwd | View examples |
| Sort text | sort names.txt | View examples |
| Sort numerically | sort -t, -k2,2n scores.csv | View examples |
| Count repeated lines | sort statuses.txt | uniq -c | View examples |
| Convert letter case | tr '[:lower:]' '[:upper:]' < names.txt | View examples |
| Delete characters | tr -d '\r' < windows.txt | View examples |
| Count lines | wc -l < app.log | View examples |
| Summarize a field | awk -F',' 'NR > 1 {print $2}' requests.csv |
sort |
uniq -c |
sort -nr | View examples |
Unix text tools are strongest when each stage performs one visible transformation. Start with read-only output, quote patterns and filenames, choose delimiters deliberately, and validate intermediate results before redirecting them into a file.
Step by step
Detailed examples
Select and exclude lines with grep
grep interprets its pattern as a basic regular expression unless -E selects extended syntax or -F requests literal matching. Quote patterns so the shell does not expand metacharacters first. Exit status 0 means a match, 1 means no match, and values above 1 indicate an error—an important distinction in scripts.
printf '%s\n' 'INFO started' 'WARN slow response' 'ERROR user[id] timeout' > app.log
grep -E 'ERROR|WARN' app.log
grep -Fn 'user[id]' app.log
grep -iv 'info' app.log WARN slow response
ERROR user[id] timeout
3:ERROR user[id] timeout
WARN slow response
ERROR user[id] timeoutprintf '%s\n' '# generated' 'port=8080' 'host=localhost' > settings.conf
grep -v '^#' settings.conf port=8080
host=localhostTransform a stream with sed
sed reads input and writes transformed text to standard output, which makes its default behavior safe for inspection. The s command replaces the first match per line unless the g flag is present; d suppresses selected lines. GNU sed's -i changes files in place, so prefer reviewed output or an explicit backup when editing valuable data.
printf '%s\n' 'http://one.test http://two.test' '' 'http://three.test' > links.txt
sed -e 's#http:#https:#g' -e '/^[[:space:]]*$/d' links.txt https://one.test https://two.test
https://three.testprintf '%s\n' 'alpha beta' 'gamma delta' | sed 's/[[:space:]]\{1,\}/ /g' alpha beta
gamma deltaProcess records and fields with awk
awk evaluates pattern-action rules for every record. -F sets the input field separator, $1 through $NF address fields, NR counts records, and END runs after all input. Simple delimiter splitting works for uncomplicated records; quoted CSV containing embedded commas needs a CSV-aware parser rather than -F,.
printf '%s\n' 'name,team,score' 'Ada,red,92' 'Grace,blue,78' 'Linus,red,85' > scores.csv
awk -F',' 'NR > 1 && $3 >= 80 {print $1, $3; sum += $3} END {print "total", sum}' scores.csv Ada 92
Linus 85
total 177Extract uncomplicated delimited columns with cut
cut selects character positions or delimiter-separated fields without interpreting a schema. Its delimiter is one character, and it does not understand quoting or escaped delimiters. It is ideal for stable formats such as /etc/passwd; use awk or a format-aware tool when selection depends on values or records are more complex.
printf '%s\n' 'ada:x:1001:1001::/home/ada:/bin/bash' 'build:x:1002:1002::/srv/build:/usr/sbin/nologin' | cut -d: -f1,7 ada:/bin/bash
build:/usr/sbin/nologinSort before grouping repeated lines
sort orders lines, with -n comparing numeric keys and -k selecting key ranges. uniq only combines adjacent equal lines, so unsorted data usually needs sort first. Locale affects text order; set LC_ALL=C only when bytewise, reproducible ordering is the intended contract. wc -l counts newline characters, which can differ from a human notion of lines when the final record lacks a newline.
printf '%s\n' ok error ok pending error ok | sort | uniq -c | sort -nr 3 ok
2 error
1 pendingprintf '%s\n' 'Ada,9' 'Grace,12' 'Linus,3' | sort -t, -k2,2n Linus,3
Ada,9
Grace,12Translate or delete character sets with tr
tr maps characters from one set to another or removes them with -d. It reads standard input rather than filenames. Quoted POSIX character classes such as [:lower:] express intent more clearly than ASCII ranges, while deleting carriage returns is useful for CRLF input only after confirming that those bytes are unwanted.
printf 'Ada\r\nGrace\r\n' | tr -d '\r' | tr '[:lower:]' '[:upper:]' ADA
GRACECompose small stages and inspect each boundary
A pipeline connects one command's standard output to the next command's standard input. Build it incrementally so field selection, normalization, and ordering can be verified independently. In production shell scripts, enable an appropriate pipeline failure policy and write to a temporary output before replacing valuable files.
printf '%s\n' 'time,method,path' '1,GET,/' '2,POST,/login' '3,GET,/docs' '4,GET,/' > requests.csv
awk -F',' 'NR > 1 {print $2}' requests.csv | sort | uniq -c | sort -nr 3 GET
1 POSTSources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



