Linux tail Command with Examples
Linux tail Command with Examples
The Linux tail command is a commonly used command-line utility for displaying the end portion of a file. By default, it shows the last 10 lines of a file.
The tail command is especially useful for Linux administrators, software developers, and software testers because application logs are continuously updated. Using tail, you can quickly inspect the latest log entries without opening the entire file.
The tail command reads a file and displays its last part on the terminal. It can display a specific number of lines or bytes and can also continuously monitor a file as new content is added.
For example, if an application generates a large log file:
application.log
Instead of displaying thousands of lines, you can use:
tail application.log
This displays the last 10 lines of the file.
Syntax of the tail Command
tail [OPTION]... [FILE]...
Commonly used options include:
| Option | Description |
|---|---|
-n |
Display the specified number of lines |
-c |
Display the specified number of bytes |
-f |
Continuously monitor a file for new content |
-F |
Follow a file and continue monitoring it even when it is recreated or rotated |
-q |
Suppress file name headers when multiple files are specified |
-v |
Always display file name headers |
1. Display the Last 10 Lines
By default, tail displays the last 10 lines.
tail application.log
Example output:
INFO User authentication successful
INFO Database connection established
INFO Request received
INFO Processing request
INFO Payment validation completed
INFO Order created
INFO Email notification sent
INFO Request completed
INFO Session updated
INFO Application running normally
2. Display the Last N Lines
Use the -n option to specify how many lines you want to display.
tail -n 5 application.log
This displays the last five lines of the file.
You can also use the shorter form:
tail -5 application.log
3. Display the Last 20 Lines
tail -n 20 server.log
This is useful when you need to inspect a larger portion of the latest log entries.
4. Monitor a Log File in Real Time
One of the most useful features of tail is the -f option.
tail -f application.log
The command continues running and displays new lines whenever they are appended to the file.
This is extremely useful for monitoring application logs while an application is running.
For example, you might see:
INFO Request received
INFO User logged in
INFO API request completed
ERROR Payment service unavailable
INFO Retrying payment request
As new log entries are written, they appear automatically in the terminal.
5. Stop Real-Time Monitoring
When using tail -f, press:
Ctrl + C
to stop monitoring and return to the shell prompt.
6. Display the Last N Bytes
The -c option displays the specified number of bytes from the end of the file.
tail -c 100 application.log
This displays the last 100 bytes of the file.
7. Monitor Multiple Log Files
You can provide multiple files to tail.
tail application.log error.log
The output normally contains the file name before the contents so that you can identify where each line came from.
You can also specify different line counts using the command options:
tail -n 5 application.log error.log
8. Suppress File Name Headers
When working with multiple files, the -q option suppresses the file name headers.
tail -q application.log error.log
This can be useful when you want cleaner command output.
9. Always Display File Names
The -v option forces tail to display the file name header.
tail -v application.log
This is particularly useful when processing multiple files.
10. Follow a File After Log Rotation
Linux applications often use log rotation. A log file may be renamed and a new file may be created with the original name.
The -F option is useful in this situation:
tail -F application.log
Unlike a simple -f operation, -F continues following the file even when the file is replaced or recreated.
11. Display Lines Starting From a Specific Line
You can use a plus sign with -n to display content starting from a particular line.
tail -n +20 application.log
This displays the file starting from line 20 through the end of the file.
12. Use tail with Another Command
The tail command can be combined with other Linux commands using pipes.
For example, to display the last five processes from ps output:
ps aux | tail -n 5
This is an example of Linux command chaining using a pipe.
13. Find Recent Errors from a Log File
A common troubleshooting technique is combining grep with tail.
grep "ERROR" application.log | tail -n 10
This finds lines containing ERROR and displays the latest 10 matching entries from the resulting output.
14. Monitor Only Errors in Real Time
You can combine tail -f with grep:
tail -f application.log | grep "ERROR"
This allows you to monitor the log continuously while displaying only lines containing ERROR.
For case-insensitive matching:
tail -f application.log | grep -i "error"
15. View Web Server Logs
The tail command is frequently used to inspect web server logs.
For example:
tail -f /var/log/nginx/access.log
Or:
tail -f /var/log/nginx/error.log
For an Apache server, you might use:
tail -f /var/log/apache2/error.log
The exact log file location depends on the Linux distribution and server configuration.
16. Monitor Application Logs During Testing
For software testers, tail is particularly useful during test execution.
Suppose an application writes test-related information to:
/opt/myapp/logs/application.log
You can monitor it with:
tail -f /opt/myapp/logs/application.log
While executing a test case, you can immediately observe:
INFO Login request received
INFO User authentication started
INFO Authentication successful
INFO Dashboard request received
ERROR Database timeout
This helps testers correlate test failures with application-side log messages.
17. Check the Latest Lines After a Test Execution
After executing a test suite, you may only need the most recent entries:
tail -n 50 test-execution.log
This is often faster than opening a very large log file.
18. Combine tail with grep and sort
Linux commands can be combined to perform more advanced log analysis.
tail -n 1000 application.log | grep "ERROR" | tail -n 20
This command:
- Reads the latest 1000 lines.
- Filters lines containing
ERROR. - Displays the last 20 matching errors.
19. Check Whether a Log File Is Being Updated
When troubleshooting an application, you can run:
tail -f application.log
If new entries appear when you perform an action in the application, you know that the application is writing to the log file.
20. Difference Between tail and head
| Command | Purpose | Typical Usage |
|---|---|---|
head |
Displays the beginning of a file | Inspect the first lines of a file |
tail |
Displays the end of a file | Inspect recent log entries |
For example:
head application.log
shows the beginning of the file, while:
tail application.log
shows its ending.
21. Difference Between tail -f and tail -F
| Command | Purpose |
|---|---|
tail -f file.log |
Continues displaying newly appended data |
tail -F file.log |
Continues following the file even when it is rotated or recreated |
22. Practical Example: Troubleshooting an Application
Imagine a Java application is running on a Linux server and users report intermittent login failures.
You could monitor the application log using:
tail -f /var/log/myapp/application.log
Then filter authentication-related errors:
tail -f /var/log/myapp/application.log | grep -i "login\|authentication\|error"
When a user reproduces the problem, the tester or developer can immediately inspect the relevant log entries.
23. Commonly Used tail Commands
| Command | Use |
|---|---|
tail file.txt |
Display the last 10 lines |
tail -n 20 file.txt |
Display the last 20 lines |
tail -f file.log |
Monitor a log file in real time |
tail -F file.log |
Follow a file across log rotation |
tail -c 100 file.txt |
Display the last 100 bytes |
tail -n +20 file.txt |
Display the file from line 20 onward |
grep "ERROR" app.log | tail -n 10 |
Display the latest 10 error entries |
Advantages of the tail Command
- Simple and fast command-line utility.
- Very useful for analyzing large log files.
- Can monitor files in real time.
- Works well with
grep,awk,sed,sort, and other Linux commands. - Very useful for application troubleshooting and production monitoring.
- Helpful for software testers investigating failures on Linux servers.
Important Points to Remember
- By default,
taildisplays the last 10 lines. - Use
-nto control the number of lines. - Use
-cto work with bytes. - Use
-ffor real-time monitoring. - Use
-Fwhen log rotation or file recreation is expected. - Press
Ctrl + Cto stoptail -f. - Combining
tailwithgrepis extremely useful for log analysis.
Conclusion
The Linux tail command is a small but extremely powerful utility for working with files and logs. Its ability to display the latest entries and continuously monitor changing files makes it an essential command for Linux administrators, developers, DevOps engineers, and software testers.
For day-to-day troubleshooting, one of the most valuable commands to remember is:
tail -f application.log
Once combined with commands such as grep, awk, and sed, tail becomes an effective tool for real-time log analysis and application troubleshooting.