You open a log to find a recent error, but lines rush past because cat prints the whole file. With a long log, first choose which part you want to read.
When should you use cat, less, head, or tail?
| Goal | Command | Scope |
|---|---|---|
| Print a short file | cat app.log | All lines in the terminal |
| Navigate a long file | less app.log | Move by screen; press q to quit |
| Read the beginning | head -n 3 app.log | First three lines |
| Read recent lines | tail -n 3 app.log | Last three lines |
Without -n 3, head and tail show ten lines by default. Start with head for initial configuration and tail for a recent error. Use less if you need to move back and forth through the full sequence.
The diagram numbers seven line positions. The 500 in the middle belongs to line four and appears in neither short output, but it was not deleted from the source log.
Compare head and tail on the same log
Make a sample log in a temporary directory. > writes a file afresh, so use only this example rather than an important file:
demo_dir=$(mktemp -d)
demo_log="$demo_dir/app.log"
printf '%s\n' \
'09:00 boot' \
'09:01 ready' \
'09:02 GET /health 200' \
'09:03 GET /orders 500' \
'09:04 restart' \
'09:05 ready' \
'09:06 GET /orders 200' > "$demo_log"
head -n 3 "$demo_log"09:00 boot
09:01 ready
09:02 GET /health 200The first three lines show startup and readiness. The last three lines show a later period:
tail -n 3 "$demo_log"09:04 restart
09:05 ready
09:06 GET /orders 200The middle 09:03 GET /orders 500 appears in neither short view. head and tail selected a display range; they did not edit the file. If you need that missing context, return to less "$demo_log".
What is the difference between tail -f and tail -n 0 -f?
tail -f "$demo_log" shows the file's current last lines, then waits for newly appended lines. The terminal prompt does not return because the command is watching, not frozen. Press Ctrl+C to stop.
Add -n 0 when you do not want to repeat existing lines. The first line below schedules another write after two seconds; the second waits for that write:
(sleep 2; echo '09:07 GET /orders 201' >> "$demo_log") &
tail -n 0 -f "$demo_log"09:07 GET /orders 201-n 0 means “show zero current lines, then show additions.” It is the wrong starting point for an error that already happened. Use tail -n 30 or less to inspect earlier context first.
What if you still cannot see the error?
Check the file path and range of lines. Reading a different app.log gives irrelevant output even with the right command. Check the current directory with pwd, then widen the range if the last three lines are insufficient.
Do not assume one incident fits one line. A multiline error may need more context than the final line. tail -f watches additions; it does not search all past causes. If output stops after log rotation, the followed file may differ from the new file, so recheck the path and update state.
Key takeaways
cat prints everything, less navigates, head shows the beginning, and tail shows the end. tail -f waits for appended lines; tail -n 0 -f starts with only future lines. When a log seems empty of errors, check the path and range before assuming the data is gone.

