RTFM · Tools
ripgrep for searching
ripgrep searches trees fast by default: recursive, respects ignore files, regex-native. It complements grep rather than replacing the POSIX toolkit.
Everyday invocations
rg ERROR /var/log/app.log # simple search
rg -i todo ~/src/ # case-insensitive recursive
rg -l 'Listen 80' /etc/ # filenames only
rg -C2 NotFound service.log # 2 lines context each side
rg -uu hidden_feature # include ignored/hidden anyway
Results arrive fast enough to iterate hypotheses interactively rather than batching queries cautiously.
Combining with pipelines
rg 'Cache-Control' nginx/*.conf | awk '{print $3}' | sort | uniq -c
Still respecting grep
grep remains POSIX-portable and universally available in minimal images; rg excels locally and interactively. Knowing both avoids either disappointment.
| grep idiom | rg equivalent |
|---|---|
| grep -rn pattern dir/ | rg pattern dir/ |
| grep -i | rg -i |
| grep -E | rg (native) |
| grep -B2 -A4 | rg -B2 -A4 |
Prove it works: search integration habitual
reaching for rg without hesitation when answering 'where is X configured?'; reflex indicates adoption complete.
Counting, replacing and reporting
Verified against the installed ripgrep 15.2.0; these flags turn rg from a search into a reporting tool.
rg -c 'Listen' /etc/ # matches PER FILE (counts)
rg --count-matches ERROR app.log # every match counted, not just lines
rg --stats ERROR app.log # human report: files, matches, bytes searched
rg -r 'proxy' 'front-end' *.conf # search AND replace display (does not edit files!)
rg -g '*.conf' -g '!*~' Listen # glob include/exclude filters
rg -w root /etc/passwd # word-bounded: no 'chroot' noise
--replace changes DISPLAY only. It will not rewrite your files; a frequent and costly assumption. For real edits, combine with sed or an editor; for inspecting what an edit WOULD look like, --replace is instant and safe.
rg in scripts: exit codes are an API
rg quiet pattern file; echo $? # -> 1 when nothing matches
rg host /etc/hostname; echo $? # -> 0 on match
rg --files /absent-dir 2>/dev/null; echo $? # -> 2 on real error
Distinguishing 'no match' from 'could not search' makes rg composable in scripts: a 1 is a legitimate answer, a 2 is a problem. Pair it with the pipeline habits from the shell-pipelines chapter; rg selects, downstream stages aggregate:
rg --no-filename 'session opened' /var/log/messages |
+ awk '{print $NF}' | sort | uniq -c | sort -rn | head
Did we miss something?
If this page left something unanswered, found an error, or there is another subject you would like documented, tell us. Saphira’s documentation grows from real problems people need to solve.
Send feedback or request a new section →
Prefer not to do it yourself?
Everything needed to do the work yourself is documented here and remains free; we charge for human time, not for withholding knowledge. Sometimes the missing resource is simply time. The same people who build Saphira can provide paid professional help with implementation, migration, troubleshooting and administration.