Module 2 · Files and directories
head, tail and following a log
Reading just the beginning or the end of a file, starting from a given line, and watching a log grow live with tail -f.
What you will learn
- Print the first or last N lines (or bytes) of a file.
- Start reading at a given line with `tail -n +N` and cut out a slice of a file.
- Follow a growing log with `tail -f` and stop it with Ctrl+C.
Very often you do not want the whole file. You want the header of a CSV to see its columns, or the last few lines of a log to see what just happened. head prints the beginning of a file and tail the end, ten lines by default. Both take -n N to choose how many, and both accept the old short form -N, so head -3 is the same as head -n 3.
~% cd /root/lab/l17
l17% head -n 3 access.log
10.0.0.2 GET /page1.html 200
10.0.0.3 GET /page2.html 200
10.0.0.4 GET /page3.html 200
l17% tail -n 2 access.log
10.0.0.3 GET /page20.html 200
10.0.0.4 GET /page21.html 200
l17% tail -n +19 access.log
10.0.0.2 GET /page19.html 200
10.0.0.3 GET /page20.html 200
10.0.0.4 GET /page21.html 200
Counting from the start: tail -n +N
A plus sign changes the meaning of tail's number: tail -n +N means *start at line N and print everything to the end*. The classic use is skipping a header: tail -n +2 data.csv gives every line except the first. head has a mirror trick: head -n -N prints everything except the last N lines.
To cut a slice out of the middle, combine the two with a pipe (lesson 24 explains | properly): head -n 12 file | tail -n 3 takes the first twelve lines and then keeps the last three of those, which are lines 10 to 12. With -c instead of -n, both commands count bytes: head -c 4 photo.png reads just the first four bytes, which you will use in lesson 19 to identify files.
| Command | Prints |
|---|---|
head FILE | The first 10 lines |
head -n 5 FILE | The first 5 lines |
head -n -5 FILE | All but the last 5 lines |
tail -n 5 FILE | The last 5 lines |
tail -n +5 FILE | From line 5 to the end |
head -c 16 FILE | The first 16 bytes |
Given several files, both commands print a small ==> name <== header before each one, so tail -n 1 *.log shows the last line of every log at once. -q drops the headers.
Following a log: tail -f
Programs write their logs by appending lines at the end. tail -f FILE (*follow*) prints the last lines and then keeps waiting, printing each new line the moment it is written. It is how administrators watch a server while they reproduce a problem. It never ends by itself: press Ctrl+C to get your prompt back. tail -F does the same but keeps retrying if the file is deleted and recreated, which happens when logs are rotated.
Commands in this lesson
| Command | What it does |
|---|---|
head -n N FILE | First N lines (10 by default). |
tail -n N FILE | Last N lines (10 by default). |
tail -n +N FILE | Everything from line N onwards. |
head -n -N FILE | Everything except the last N lines. |
head -c N FILE | First N bytes. |
tail -f FILE | Follow a growing file; Ctrl+C to stop. |
Quiz
How many lines does `head notes.txt` print if you give no option?
- 1
- 10
- As many as fit on the screen
What does `tail -n +2 data.csv` print?
- The last two lines
- Every line except the first
- Only line 2
Which command prints lines 10 to 12 of a file?
- `head -n 12 file | tail -n 3`
- `tail -n 12 file | head -n 10`
- `head -n 10-12 file`
You started `tail -f app.log` and the prompt does not come back. Is something wrong?
- Yes, the file is too big
- No, it is waiting for new lines; Ctrl+C stops it
- Yes, the VM has frozen
What does `head -c 4 photo.png` show?
- The first four lines
- The first four bytes
- The four largest pixels
Practice
Save the first 5 lines of /root/lab/l17/access.log into /root/lab/l17/first5.txt.
Save every line of /root/lab/l17/access.log from line 19 to the end into /root/lab/l17/tail.txt.
Follow /root/lab/l17/app.log live, so that new lines appear as they are written. (Ctrl+C to stop.)
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.