grep1-3 Exercise 1: Date, Time, Then ERROR or WARN =================================================== cat > server.log <<'EOF' 2026-10-08 09:14:02 INFO started 2026-10-08 09:15:11 WARN slow query 2026-10-08 09:15:48 ERROR disk full 10-08 09:20:00 ERROR bad date format 2026-10-08 09:21:30 error lowercase 2026-10-08 09:22:00 ERROR indented 2026-10-08 09:30:00 WARNING not a WARN 2026-10-08 09:31:00 ERROR timeout EOF grep -E '^[0-9]{4}-[0-9]{2}-[0-9]{2} [0-9]{2}:[0-9]{2}:[0-9]{2} (ERROR|WARN) ' server.log Output: 2026-10-08 09:15:11 WARN slow query 2026-10-08 09:15:48 ERROR disk full 2026-10-08 09:31:00 ERROR timeout WHY THIS WORKS AS AN ANSWER --------------------------- ^ pins the start, so the indented line (which begins with spaces) is out. {4}, {2} and {2} after [0-9] insist on a full date and time, so '10-08 09:20:00' is out. (ERROR|WARN) is a group with an either-or, which needs -E so that the | and the parentheses are operators without backslashes. The final space is what excludes WARNING: the pattern needs WARN followed by a space, and WARNING has an I there. Lowercase 'error' is out because the match is case-sensitive. Three lines remain: the WARN and the two ERRORs with a clean timestamp. -w would NOT do this job: it would accept the indented line, and the date format is not checked.