Viewing files: cat, less, head & tail
Read files of any size, follow logs live with tail -f, and inspect files with wc, file and stat.
Reading files is a huge part of working on Linux: configuration files, logs, CSVs, scripts, documentation. Different tools suit different jobs. cat for small files, less for big ones, head and tail for the start and end, and tail -f to watch logs live.
Sample files#
cat: print whole files#
cat (short for concatenate) can join several files, too: cat part1.txt part2.txt > whole.txt. It's perfect for short files. For anything longer than a screen, use less. tac prints a file backwards, last line first.
less: page through anything#
less opens the file one screen at a time and doesn't load it all into memory, so even multi-gigabyte logs open instantly.
Useful options: less -N shows line numbers, and less +G file starts at the end. man pages are displayed with less, so these keys work there too. You can also pipe any long output into it: ps aux | less.
head and tail: the start and the end#
More forms:
tail -f: watch logs live#
This is one of the most-used commands on any server:
-f (follow) keeps the file open and prints new lines as they're written. Press Ctrl+C to stop. Variations:
tail -F filekeeps following even when the log is rotated (renamed and recreated), which is usually what you want.tail -f app.log | grep ERRORfollows only matching lines.tail -f a.log b.logfollows several files, with headers.- For systemd services, use
journalctl -u nginx -finstead (see systemd services).
wc: counting#
wc prints lines, words and bytes. -l, -w and -c select one count, and -m counts characters (which differs from bytes for UTF-8 text).
What kind of file is it?#
Before opening an unknown file, check what it is, since cat on a binary file fills your terminal with garbage:
If your terminal does get garbled, type reset and press Enter. To peek inside a binary safely, use strings file | less (printable text only) or xxd file | head (a hex dump).
stat: full details#
You'll see size, permissions (in both octal and symbolic form), owner, inode number and timestamps. Modify is when the content last changed, and Change is when the metadata (permissions, owner) last changed. Your numbers will differ.
Comparing files#
2c2 means "line 2 changed". In unified format, - lines are removed and + lines added. cmp compares binary files byte by byte, and sha256sum file prints a checksum for verifying downloads.
Viewing compressed files#
Logs are often rotated into .gz files. You don't need to decompress them first:
zless pages through compressed files like less.
Which tool when?#
Common mistakes#
cat-ing huge or binary files and flooding the terminal. Useless, or check withfilefirst. If the terminal gets garbled, typereset.- Forgetting that
tail -fkeeps running. Press Ctrl+C to stop following. - Using
tail -fon rotated logs. Usetail -F, which reopens the file when it's replaced. - Opening a file in an editor just to read it. That risks accidental changes;
lessis safer.
What's next#
Reading files is half the job; now you'll edit them with nano and vim.
Check your understanding
Quick quiz
1.Which command is best for reading a 2 GB log file?
2.How do you watch new lines being written to a log file in real time?
3.What does
wc -l access.logprint?
Finished reading?
Mark this lesson complete to track your progress.