kmail.at
← learning

linux · difficulty ◆◆

grep — search text using patterns

Find a needle in the haystack. Then find every needle.

Every time you run `history | grep ssh` you are using a tool that was born as a throwaway edit command in a 1960s text editor — and it has been the backbone of Unix search ever since.

2026-08-12 · 6 min read

$ grep

What it does

grep searches input for lines that match a pattern (a plain string or a regular expression) and prints the matching lines. It works on files, or on anything piped into it, which makes it the glue of the Unix text pipeline.

Why it matters

grep is the universal "search inside text" tool. Combined with pipes, it filters the output of any command: `ps aux | grep python`, `history | grep ssh`. Master grep and you master the art of finding things in Unix.

Example

$ grep -n 'error' server.log
42:  [ERROR] database connection timeout
58:  [ERROR] failed to bind port 8080
77:  [ERROR] worker crashed after retry

-n prints line numbers so you can jump straight to the match.

$ grep -ri 'todo' src/
src/app.ts:15:  // TODO: handle null user
src/utils.ts:88:  // todo: validate email format

-r searches recursively, -i ignores case.

Common flags

-n
print line numbers of matches
-i
case-insensitive matching
-r
recursively search directories
-v
invert — print lines that do NOT match
-c
count matching lines instead of printing them
-E
extended regex (same as egrep)

History

Origin

grep was born in 1973 when Ken Thompson extracted a search routine from the QED text editor to make a standalone tool. Its name comes from the QED command "g/re/p" — "globally search for a regular expression and print matching lines". Thompson typed it so often he just made it a program.

Fun fact

In 1987, Mike Haertel produced the first freely-redistributable grep (a forerunner of GNU grep), which quickly became the standard. GNU grep is now so fast that for many files it can search faster than the disk can deliver the data.

Fun facts

Pros & cons

pros

  • + The standard every other search tool is measured against
  • + Works on files, streams, and pipes — the glue of the Unix pipeline
  • + Extremely fast on literal strings thanks to Boyer-Moore
  • + Universal: present on every Unix-like system since 1973

cons

  • − Line-oriented by default — no cross-line or multi-line matching without -P or z
  • − Basic regex syntax is surprising; metacharacters need escaping
  • − Slower than ripgrep (rg) on huge source trees with complex patterns
  • − No built-in output colour unless you pass --color=auto

Takeaways

  1. 1Reach for -E for readable extended regex — stop fighting basic-regex escapes
  2. 2Use -i for case-insensitive, -r for recursive, -n for line numbers
  3. 3Use -v to invert and -c to count when you care about volume, not detail
  4. 4Pipe command output into grep: `ps aux | grep ssh`, `history | grep npm`
  5. 5For huge codebases, switch to ripgrep (rg) — same idea, faster engine

Related commands

← all learning