Reading and searching text: logs and output
Most troubleshooting on Linux is reading text: log files, command output and configuration. less lets you page through a file, head and tail show the start and end, grep finds lines that match, and the pipe | feeds one command's output into the next.
Looking inside files
| Command | Use it for |
|---|---|
cat app.conf | Print a short file in one go |
less server.log | Page through a long file. Space for the next page, /word to search, n for the next match, q to quit |
head -n 20 build.log | The first 20 lines |
tail -n 50 build.log | The last 50 lines, which is usually where the error is |
tail -f server.log | Follow the file and print new lines as they are written. Ctrl+C stops it |
wc -l data.csv | Count the lines |
grep: find the lines that matter
grep prints every line that contains a pattern. It is the quickest way to find an error in thousands of lines of output.
$ grep ERROR server.log 2026-10-09 10:14:03 ERROR Connection refused: db01:5432 $ grep -i timeout server.log # -i ignores upper and lower case $ grep -n ERROR server.log # -n shows the line number $ grep -r "db01" config/ # -r searches every file under a folder $ grep -v DEBUG server.log # -v shows the lines that do NOT match
Pipes and redirection
The pipe | sends the output of one command into the input of the next. Small commands chained together answer real questions. grep ERROR server.log | wc -l counts the errors. ps -ef | grep java finds Java processes. history | grep ssh finds an ssh command you typed earlier.
Redirection sends output to a file instead of the screen. > creates the file or overwrites it, and >> adds to the end. 2> redirects error messages, which travel separately from normal output.
ls > files.txtdate >> run.logmake 2> errors.txtmake > build.txt 2>&1Which command shows only the lines containing the word ERROR in app.log?
Show a hint
One command, the pattern, then the file name.
Show the solution
grep ERROR app.log
Examples are for learning. Run commands and jobs only on a system you are authorised to use, such as a training or test system, and never on production without approval.
Common mistakes
cat dumps the whole file and the start scrolls away. Use less, or tail for the newest lines.
grep error does not match ERROR. Add -i when you are not sure how the message is written.
> replaces the file. Use >> to add to it, or write to a new file.
What you will see at work
- When a pipeline step fails, the last 50 lines of its log (
tail -n 50) usually contain the reason. tail -fon an application log while you test is the Linux equivalent of watching a job's output arrive in SDSF.- Paste the exact error line into tickets and chats. 'It failed' gets no help; the line from grep does.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.