shell · difficulty ◆
tail — show the last lines of a file
The end of the file is where the action is — and tail is how you watch it.
$ tailWhat it does
tail prints the last 10 lines of a file (or of anything piped into it) to the terminal. It is the mirror image of head. What makes tail indispensable is its -f flag: 'follow' mode watches a file and keeps printing new lines as they are appended, turning a static log into a live, scrolling stream of events.
Why it matters
Errors land at the end of files, and the newest data is what you care about. tail -f is the go-to way to watch a web server or application log in real time, which is why every debugging session on a server starts with it. Combined with grep, tail filters a live stream down to exactly the messages you are hunting for.
Example
$ tail -n 3 /var/log/syslogAug 23 09:20:01 kmail-web CRON[4182]: (root) CMD (command -v debian-sa1 > /dev/null && debian-sa1 1 1)
Aug 23 09:21:15 kmail-web systemd[1]: Started Session 42 of user kmail.
Aug 23 09:22:00 kmail-web nginx[3172]: 203.0.113.8 - - [23/Aug/2026:09:22:00] "GET /tutorials HTTP/1.1" 200 4512-n 3 shows the last 3 lines. Without it, tail shows the default last 10.
$ tail -f /var/log/nginx/access.log203.0.113.5 - - [23/Aug/2026:09:25:01] "GET /tutorials/gzip HTTP/1.1" 200 3144
203.0.113.5 - - [23/Aug/2026:09:25:03] "GET /assets/app.js HTTP/1.1" 200 88110
203.0.113.7 - - [23/Aug/2026:09:25:11] "GET /tutorials/tail HTTP/1.1" 200 2960-f follows the file: tail keeps running and prints each new line as it is appended. Press Ctrl-C to stop.
Common flags
- -n N
- print the last N lines instead of the default 10
- -f
- follow — keep watching the file and print new lines as they are appended
- -F
- follow with retry — keep following even if the file is renamed or rotated (watch logs safely)
- -c N
- print the last N bytes instead of lines
- -q
- quiet — suppress headers when printing multiple files
- -n +N
- start printing from line N onward, not the end of the file
History
Origin
tail has been part of Unix since the 1970s, appearing alongside head in the earliest Bell Labs systems. Its name is simply descriptive — it shows the tail (end) of a file. The -f follow mode is just as old, added early on because system operators needed to watch log files live as programs appended to them.
Fun fact
tail -F is the rotation-safe version of -f: it reopens the file when it is replaced, which is exactly what you want when logrotate swaps a log out. This one-letter difference is why monitoring scripts use -F and interactive sessions get away with -f.