Read

Module 2 · Files and directories

head, tail and following a log

Reading just the beginning or the end of a file, starting from a given line, and watching a log grow live with tail -f.

What you will learn

  • Print the first or last N lines (or bytes) of a file.
  • Start reading at a given line with `tail -n +N` and cut out a slice of a file.
  • Follow a growing log with `tail -f` and stop it with Ctrl+C.

Very often you do not want the whole file. You want the header of a CSV to see its columns, or the last few lines of a log to see what just happened. head prints the beginning of a file and tail the end, ten lines by default. Both take -n N to choose how many, and both accept the old short form -N, so head -3 is the same as head -n 3.

~% cd /root/lab/l17
l17% head -n 3 access.log
10.0.0.2 GET /page1.html 200
10.0.0.3 GET /page2.html 200
10.0.0.4 GET /page3.html 200
l17% tail -n 2 access.log
10.0.0.3 GET /page20.html 200
10.0.0.4 GET /page21.html 200
l17% tail -n +19 access.log
10.0.0.2 GET /page19.html 200
10.0.0.3 GET /page20.html 200
10.0.0.4 GET /page21.html 200

Counting from the start: tail -n +N

A plus sign changes the meaning of tail's number: tail -n +N means *start at line N and print everything to the end*. The classic use is skipping a header: tail -n +2 data.csv gives every line except the first. head has a mirror trick: head -n -N prints everything except the last N lines.

To cut a slice out of the middle, combine the two with a pipe (lesson 24 explains | properly): head -n 12 file | tail -n 3 takes the first twelve lines and then keeps the last three of those, which are lines 10 to 12. With -c instead of -n, both commands count bytes: head -c 4 photo.png reads just the first four bytes, which you will use in lesson 19 to identify files.

CommandPrints
head FILEThe first 10 lines
head -n 5 FILEThe first 5 lines
head -n -5 FILEAll but the last 5 lines
tail -n 5 FILEThe last 5 lines
tail -n +5 FILEFrom line 5 to the end
head -c 16 FILEThe first 16 bytes

Given several files, both commands print a small ==> name <== header before each one, so tail -n 1 *.log shows the last line of every log at once. -q drops the headers.

Following a log: tail -f

Programs write their logs by appending lines at the end. tail -f FILE (*follow*) prints the last lines and then keeps waiting, printing each new line the moment it is written. It is how administrators watch a server while they reproduce a problem. It never ends by itself: press Ctrl+C to get your prompt back. tail -F does the same but keeps retrying if the file is deleted and recreated, which happens when logs are rotated.

Commands in this lesson

CommandWhat it does
head -n N FILEFirst N lines (10 by default).
tail -n N FILELast N lines (10 by default).
tail -n +N FILEEverything from line N onwards.
head -n -N FILEEverything except the last N lines.
head -c N FILEFirst N bytes.
tail -f FILEFollow a growing file; Ctrl+C to stop.

Quiz

  1. How many lines does `head notes.txt` print if you give no option?

    • 1
    • 10
    • As many as fit on the screen
  2. What does `tail -n +2 data.csv` print?

    • The last two lines
    • Every line except the first
    • Only line 2
  3. Which command prints lines 10 to 12 of a file?

    • `head -n 12 file | tail -n 3`
    • `tail -n 12 file | head -n 10`
    • `head -n 10-12 file`
  4. You started `tail -f app.log` and the prompt does not come back. Is something wrong?

    • Yes, the file is too big
    • No, it is waiting for new lines; Ctrl+C stops it
    • Yes, the VM has frozen
  5. What does `head -c 4 photo.png` show?

    • The first four lines
    • The first four bytes
    • The four largest pixels

Practice

  1. Save the first 5 lines of /root/lab/l17/access.log into /root/lab/l17/first5.txt.

  2. Save every line of /root/lab/l17/access.log from line 19 to the end into /root/lab/l17/tail.txt.

  3. Follow /root/lab/l17/app.log live, so that new lines appear as they are written. (Ctrl+C to stop.)

Open this lesson in the app to do the tasks in a real Linux machine and have them checked.