Skip to content

RTFM · Tools

ripgrep for searching

ripgrep searches trees fast by default: recursive, respects ignore files, regex-native. It complements grep rather than replacing the POSIX toolkit.

Saphira Linux dragon mascot

Everyday invocations

rg vocabulary
rg ERROR /var/log/app.log         # simple search
rg -i todo ~/src/                  # case-insensitive recursive
rg -l 'Listen 80' /etc/            # filenames only
rg -C2 NotFound service.log        # 2 lines context each side
rg -uu hidden_feature              # include ignored/hidden anyway

Results arrive fast enough to iterate hypotheses interactively rather than batching queries cautiously.

Combining with pipelines

rg inside pipelines
rg 'Cache-Control' nginx/*.conf | awk '{print $3}' | sort | uniq -c

Still respecting grep

grep remains POSIX-portable and universally available in minimal images; rg excels locally and interactively. Knowing both avoids either disappointment.

Quick mapping
grep idiomrg equivalent
grep -rn pattern dir/rg pattern dir/
grep -irg -i
grep -Erg (native)
grep -B2 -A4rg -B2 -A4

Prove it works: search integration habitual

reaching for rg without hesitation when answering 'where is X configured?'; reflex indicates adoption complete.

Counting, replacing and reporting

Verified against the installed ripgrep 15.2.0; these flags turn rg from a search into a reporting tool.

Beyond line printing
rg -c 'Listen' /etc/            # matches PER FILE (counts)
rg --count-matches ERROR app.log # every match counted, not just lines
rg --stats ERROR app.log         # human report: files, matches, bytes searched
rg -r 'proxy' 'front-end' *.conf # search AND replace display (does not edit files!)
rg -g '*.conf' -g '!*~' Listen   # glob include/exclude filters
rg -w root /etc/passwd           # word-bounded: no 'chroot' noise

--replace changes DISPLAY only. It will not rewrite your files; a frequent and costly assumption. For real edits, combine with sed or an editor; for inspecting what an edit WOULD look like, --replace is instant and safe.

rg in scripts: exit codes are an API

Three states, verified live: 0 match, 1 no-match, 2 error
rg quiet pattern file; echo $?   # -> 1 when nothing matches
rg host /etc/hostname;  echo $?  # -> 0 on match
rg --files /absent-dir 2>/dev/null; echo $?  # -> 2 on real error

Distinguishing 'no match' from 'could not search' makes rg composable in scripts: a 1 is a legitimate answer, a 2 is a problem. Pair it with the pipeline habits from the shell-pipelines chapter; rg selects, downstream stages aggregate:

rg as stage one
rg --no-filename 'session opened' /var/log/messages |
+  awk '{print $NF}' | sort | uniq -c | sort -rn | head

Did we miss something?

If this page left something unanswered, found an error, or there is another subject you would like documented, tell us. Saphira’s documentation grows from real problems people need to solve.

Send feedback or request a new section →

Prefer not to do it yourself?

Everything needed to do the work yourself is documented here and remains free; we charge for human time, not for withholding knowledge. Sometimes the missing resource is simply time. The same people who build Saphira can provide paid professional help with implementation, migration, troubleshooting and administration.

Ask about professional support →