← All cheat sheets

AWK COMMAND

Plain-text reference · 13 KB. Read it, search it (Ctrl-F) or print it.

BASIC SYNTAX#

awk [options] 'pattern {action}' file
awk -f script.awk file                   # Run AWK script from file
awk -F ':' '{print $1}' file             # Set field separator
awk -v var=value '{print var}' file      # Pass variable to AWK

PRINTING FIELDS#

awk '{print}' file                       # Print all lines
awk '{print $0}' file                    # Print entire line
awk '{print $1}' file                    # Print first field
awk '{print $2}' file                    # Print second field
awk '{print $NF}' file                   # Print last field
awk '{print $(NF-1)}' file               # Print second-to-last field
awk '{print $1, $3}' file                # Print fields 1 and 3
awk '{print $1 $2}' file                 # Concatenate without separator
awk '{print $1 "-" $2}' file             # Concatenate with custom separator

FIELD SEPARATORS#

awk -F ':' '{print $1}' /etc/passwd      # Colon separator
awk -F '\t' '{print $1}' file            # Tab separator
awk -F ',' '{print $1}' file.csv         # Comma separator (CSV)
awk -F '[,;]' '{print $1}' file          # Multiple separators
awk 'BEGIN {FS=":"} {print $1}' file     # Set FS in BEGIN block
awk 'BEGIN {FS=OFS=":"} {print $1,$2}' file  # Input and output separator

OUTPUT SEPARATORS#

awk 'BEGIN {OFS=","} {print $1,$2}' file     # Output field separator
awk 'BEGIN {ORS="\n\n"} {print}' file        # Output record separator
awk '{print $1,$2}' OFS=":" file             # Set OFS on command line

BUILT-IN VARIABLES#

NR      # Current record (line) number
NF      # Number of fields in current record
FS      # Field separator (default: whitespace)
OFS     # Output field separator (default: space)
RS      # Record separator (default: newline)
ORS     # Output record separator (default: newline)
FILENAME # Current filename being processed
FNR     # Record number in current file

awk '{print NR, $0}' file                # Add line numbers
awk '{print NF}' file                    # Count fields per line
awk 'END {print NR}' file                # Total line count
awk '{print FILENAME, NR, $0}' file      # Show filename with line

PATTERN MATCHING#

awk '/pattern/ {print}' file             # Lines matching pattern
awk '!/pattern/ {print}' file            # Lines NOT matching pattern
awk '/start/,/end/ {print}' file         # Range between patterns
awk '$1 ~ /pattern/' file                # Field 1 matches pattern
awk '$1 !~ /pattern/' file               # Field 1 doesn't match
awk '/error/ && /critical/' file         # Both patterns match
awk '/error/ || /warning/' file          # Either pattern matches

COMPARISON OPERATORS#

awk '$1 == "value"' file                 # Equal to string
awk '$1 != "value"' file                 # Not equal to string
awk '$1 > 100' file                      # Greater than
awk '$1 >= 100' file                     # Greater than or equal
awk '$1 < 100' file                      # Less than
awk '$1 <= 100' file                     # Less than or equal
awk '$1 > 10 && $1 < 100' file           # Range check

NUMERIC OPERATIONS#

awk '{sum += $1} END {print sum}' file               # Sum column
awk '{sum += $1} END {print sum/NR}' file            # Average
awk '{if ($1 > max) max = $1} END {print max}' file  # Maximum
awk 'BEGIN {min = 999999} {if ($1 < min) min = $1} END {print min}' file  # Minimum
awk '{print $1 + $2}' file                           # Add fields
awk '{print $1 * $2}' file                           # Multiply fields
awk '{print $1 / $2}' file                           # Divide fields
awk '{print $1 % $2}' file                           # Modulo
awk '{print $1 ^ 2}' file                            # Power/exponent

BEGIN AND END BLOCKS#

awk 'BEGIN {print "Header"} {print} END {print "Footer"}' file
awk 'BEGIN {count=0} {count++} END {print count}' file
awk 'BEGIN {FS=":"; OFS=","} {print $1,$2}' file
awk 'END {print "Total lines:", NR}' file

CONDITIONAL STATEMENTS#

awk '{if ($1 > 100) print "High"; else print "Low"}' file
awk '{if ($1 > 100) print $0}' file
awk '{result = ($1 > 100) ? "High" : "Low"; print result}' file
awk '{
    if ($1 > 100) print "High"
    else if ($1 > 50) print "Medium"
    else print "Low"
}' file

LOOPS#

# For loop over fields
awk '{for (i=1; i<=NF; i++) print $i}' file

# While loop
awk '{i=1; while (i<=NF) {print $i; i++}}' file

# Do-while loop
awk '{i=1; do {print $i; i++} while (i<=NF)}' file

# Loop with continue/break
awk '{for (i=1; i<=NF; i++) {if ($i == "skip") continue; print $i}}' file

ARRAYS#

awk '{arr[$1]++} END {for (k in arr) print k, arr[k]}' file     # Count occurrences
awk '{arr[NR]=$0} END {for (i=NR; i>0; i--) print arr[i]}' file # Reverse lines
awk '{delete arr[$1]}' file                                      # Delete element
awk '{arr[$1,$2]=$3}' file                                      # Multi-dimensional
awk 'END {asorti(arr); for (i in arr) print arr[i]}' file       # Sort array

STRING FUNCTIONS#

awk '{print length($0)}' file                        # String length
awk '{print substr($0, 1, 5)}' file                  # Substring (start, length)
awk '{print index($0, "pattern")}' file              # Find position
awk '{print tolower($0)}' file                       # Convert to lowercase
awk '{print toupper($0)}' file                       # Convert to uppercase
awk '{split($0, arr, ":")}' file                     # Split into array
awk '{gsub(/old/, "new"); print}' file               # Global substitute
awk '{sub(/old/, "new"); print}' file                # Substitute first match
awk '{print sprintf("%05d", $1)}' file               # Formatted string

TEXT REPLACEMENT#

awk '{gsub(/foo/, "bar"); print}' file               # Replace all occurrences
awk '{sub(/foo/, "bar"); print}' file                # Replace first occurrence
awk '{gsub(/foo/, "bar", $2); print}' file           # Replace in specific field
awk '{$2 = "new"; print}' file                       # Replace entire field
awk 'gsub(/pattern/, "&_suffix")' file               # Append to matched text

FORMATTED OUTPUT#

awk '{printf "%s\n", $1}' file                       # String
awk '{printf "%d\n", $1}' file                       # Integer
awk '{printf "%f\n", $1}' file                       # Float
awk '{printf "%.2f\n", $1}' file                     # Float with 2 decimals
awk '{printf "%10s\n", $1}' file                     # Right-aligned (width 10)
awk '{printf "%-10s\n", $1}' file                    # Left-aligned (width 10)
awk '{printf "%05d\n", $1}' file                     # Zero-padded integer
awk '{printf "%s - %d\n", $1, $2}' file              # Multiple fields

LINE SELECTION#

awk 'NR==1' file                                     # First line only
awk 'NR==10' file                                    # 10th line only
awk 'NR>=10 && NR<=20' file                          # Lines 10-20
awk 'NR % 2 == 0' file                               # Even lines
awk 'NR % 2 == 1' file                               # Odd lines
awk 'NR > 1' file                                    # Skip header (first line)
awk 'END {print}' file                               # Last line only
awk 'length($0) > 80' file                           # Lines longer than 80 chars
awk 'NF > 0' file                                    # Non-empty lines
awk 'NF == 0' file                                   # Empty lines only

CUSTOM FUNCTIONS#

awk 'function sum(a, b) {return a + b} {print sum($1, $2)}' file
awk 'function abs(x) {return (x < 0) ? -x : x} {print abs($1)}' file
awk 'function max(a, b) {return (a > b) ? a : b} {print max($1, $2)}' file

MULTIPLE FILES#

awk '{print FILENAME, $0}' file1 file2               # Print filename with each line
awk 'FNR==1 {print "---", FILENAME, "---"} {print}' file1 file2  # Header per file
awk 'NR==FNR {arr[$1]; next} $1 in arr' file1 file2  # Lines in file2 matching file1

FILE OUTPUT#

awk '{print > "output.txt"}' file                    # Redirect to file
awk '{print >> "output.txt"}' file                   # Append to file
awk '{print $1 > "col1.txt"; print $2 > "col2.txt"}' file  # Multiple outputs
awk '{if ($1 > 50) print > "high.txt"; else print > "low.txt"}' file

EXTERNAL COMMANDS#

awk '{system("date")}' file                          # Execute shell command
awk '{cmd = "echo " $1; system(cmd)}' file           # Dynamic command
awk '{print $0 | "sort"}' file                       # Pipe to command
awk 'BEGIN {"date" | getline date; print date}'      # Get command output

SPECIAL PATTERNS#

awk '1' file                                         # Print all (always true)
awk '0' file                                         # Print nothing (always false)
awk '{print; print ""}' file                         # Double-space output
awk 'BEGIN {print "Start"}'                          # No file needed
awk '/pattern/ {print; exit}' file                   # Print first match and exit
awk '{arr[NR]=$0} END {for(i=NR;i>0;i--)print arr[i]}' file  # Reverse file

PRACTICAL EXAMPLES#

# Count unique values in column 1
awk '{count[$1]++} END {for (val in count) print val, count[val]}' file

# Remove duplicate lines
awk '!seen[$0]++' file

# Sum column 2 grouped by column 1
awk '{sum[$1] += $2} END {for (key in sum) print key, sum[key]}' file

# Print lines between two patterns (exclusive)
awk '/START/{flag=1; next} /END/{flag=0} flag' file

# Join lines with comma
awk '{printf "%s%s", sep, $0; sep=","} END {print ""}' file

# Extract specific columns from CSV
awk -F',' '{print $1","$3","$5}' file.csv

# Calculate percentage
awk '{pct = ($1 / $2) * 100; printf "%.2f%%\n", pct}' file

# Find and print duplicate lines
awk 'seen[$0]++' file

# Add header to output
awk 'BEGIN {print "Name\tValue"} {print $1"\t"$2}' file

# Convert CSV to TSV
awk -F',' 'BEGIN {OFS="\t"} {$1=$1; print}' file.csv

LOG ANALYSIS#

# Extract IP addresses
awk '/[0-9]+\.[0-9]+\.[0-9]+\.[0-9]+/ {print}' log

# Count requests per IP
awk '{ip[$1]++} END {for (i in ip) print ip[i], i}' access.log | sort -rn

# Find 404 errors
awk '$9 == 404 {print $7}' access.log

# Count HTTP status codes
awk '{codes[$9]++} END {for (c in codes) print c, codes[c]}' access.log

# Extract failed login attempts
awk '/Failed password/ {print $(NF-3)}' /var/log/auth.log

# Parse Apache log - top requested URLs
awk '{urls[$7]++} END {for (u in urls) print urls[u], u}' access.log | sort -rn | head

# Bandwidth per IP
awk '{bytes[$1] += $10} END {for (ip in bytes) print bytes[ip], ip}' access.log | sort -rn

# Requests per hour
awk '{hour = substr($4, 14, 2); count[hour]++} END {for (h in count) print h":00", count[h]}' access.log

SECURITY ANALYSIS#

# Detect potential SQL injection attempts
awk '/SELECT|UNION|INSERT|UPDATE|DELETE|DROP|--/ {print}' access.log

# Find suspicious user agents
awk '/sqlmap|nikto|nmap|masscan/ {print $0}' access.log

# Count connections per source IP
awk '{conn[$1]++} END {for (ip in conn) if (conn[ip] > 100) print ip, conn[ip]}' access.log

# Extract unique IPs accessing admin pages
awk '/\/admin/ {ips[$1]++} END {for (ip in ips) print ip}' access.log

# Find brute force attempts (same IP, multiple failures)
awk '/Failed/ {fails[$1]++} END {for (ip in fails) if (fails[ip] > 5) print ip, fails[ip]}' auth.log

DATA PROCESSING#

# Calculate column statistics
awk '{
    sum += $1
    sumsq += $1^2
    count++
}
END {
    avg = sum/count
    std = sqrt(sumsq/count - avg^2)
    print "Count:", count
    print "Sum:", sum
    print "Average:", avg
    print "Std Dev:", std
}' data.txt

# Transpose rows to columns
awk '{
    for (i=1; i<=NF; i++) {
        arr[NR,i] = $i
    }
    if (NF > max_nf) max_nf = NF
}
END {
    for (j=1; j<=max_nf; j++) {
        for (i=1; i<=NR; i++) {
            printf "%s%s", arr[i,j], (i==NR ? "\n" : "\t")
        }
    }
}' file

AWK VS GAWK#

gawk -i inplace '{gsub(/old/,"new")}1' file    # In-place editing (GNU awk)
gawk 'BEGIN {IGNORECASE=1} /pattern/' file     # Case-insensitive (GNU awk)
gawk '{print strftime("%Y-%m-%d", $1)}' file   # Time formatting (GNU awk)
gawk 'match($0, /regex/, arr) {print arr[1]}' file  # Capture groups (GNU awk)

QUICK REFERENCE#

awk '{print $1}' file                 # First column
awk -F: '{print $1}' file             # Custom delimiter
awk '/pattern/' file                  # Grep-like filter
awk 'NR>1' file                       # Skip header
awk '{sum+=$1} END {print sum}' file  # Sum column
awk '!seen[$0]++' file                # Remove duplicates
awk '{print NF}' file                 # Count fields
awk 'END {print NR}' file             # Count lines
awk '{gsub(/old/,"new")}1' file       # Find/replace
awk 'length>80' file                  # Long lines

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.