tail Command Explained
tail shows you the end of a file, and its -f flag turns it into one of the single most-used commands for anyone who spends time watching logs, which is to say, almost everyone who administers a Linux system.
Basic usage
tail file.log
# prints the last 10 lines by default
tail -n 50 file.log
# last 50 lines instead of the default 10
Since most logs append new entries at the bottom, tail’s default behavior of showing the last 10 lines naturally surfaces the most recent activity, which is almost always what you actually want to check first.
The essential flag: tail -f
tail -f /var/log/nginx/access.log
-f (follow) is what elevates tail from a simple “show me the end of this file” tool into a live monitoring tool. After printing the initial last lines, it keeps running and watching the file, printing each new line the instant it gets appended. This is the standard way to watch a service’s output in real time: while deploying a change, reproducing a bug, or just keeping an eye on activity as it happens.
# Press Ctrl+C to stop following and return to your shell
tail -f /var/log/syslog
^C
Since tail -f runs indefinitely, waiting for new content, it never exits on its own. Ctrl+C is the standard way to stop it.
tail -f vs tail -F: handling log rotation
tail -f /var/log/app.log
# watches the currently open file descriptor
# ... later, logrotate renames the old file and creates
# a fresh empty app.log in its place ...
# tail -f is now watching a file that has been renamed away,
# and will NOT see any new lines written to the new app.log
This is a subtle but important gotcha. tail -f follows the specific file it opened, not the filename. If a log rotation tool like logrotate renames the current log and creates a new empty file with the original name, plain tail -f keeps watching the old, now-orphaned file and silently stops receiving updates.
tail -F /var/log/app.log
# capital F: also watches for the file being replaced,
# and automatically switches to following the new file
-F (capital) is a safer default for any long-running monitoring session on a system where log rotation is active, which is essentially all production servers, since it correctly detects and follows the file across a rotation event instead of getting stuck watching a stale, disconnected file handle.
Showing lines from a specific point: tail -n +N
tail -n +5 file.txt
# shows every line from line 5 to the end of the file
The + prefix changes the meaning from “the last N lines” to “starting from line N.” This is a less common but genuinely useful pattern, for example skipping a known fixed-size header in a file and printing everything after it.
Following multiple files at once
tail -f /var/log/nginx/access.log /var/log/nginx/error.log
# ==> /var/log/nginx/access.log <==
# 192.168.1.10 - - [09/Jul/2026:10:15:00] "GET / HTTP/1.1" 200
#
# ==> /var/log/nginx/error.log <==
# 2026/07/09 10:15:05 [error] connect() failed
When following more than one file, tail interleaves new lines as they arrive from either source, printing a header labeling which file a new batch of lines came from whenever the active source switches, which makes it practical to keep an eye on related logs (like a web server’s access and error logs) simultaneously in one terminal.
Combining tail with grep for live filtering
tail -f /var/log/nginx/access.log | grep --line-buffered "50[0-9]"
# live-follow the access log, showing only lines matching
# a 5xx server error status code as they happen
--line-buffered is important here: without it, grep’s output buffering can delay when matched lines actually appear on screen when its output is piped rather than going directly to a terminal, which defeats the purpose of watching something in real time.
Frequently Asked Questions
What does the tail command do?
tail prints the end of a file, ten lines by default. It is the standard way to check the most recent entries in a file, most commonly a log file where new activity is continuously appended to the bottom.
What does tail -f do and why is it so commonly used?
tail -f (follow) keeps tail running after printing the last lines, continuously watching the file and printing new lines the instant they are appended. This makes it the standard way to watch a live log file in real time, for example monitoring a web server’s access log or an application’s output while reproducing a bug, without needing to repeatedly rerun tail manually.
How do I stop tail -f once I am done watching a file?
Press Ctrl+C to stop the follow and return control to your shell. Since tail -f runs indefinitely by design, waiting for new lines to appear, it does not exit on its own; Ctrl+C is the standard way to interrupt it.
What is the difference between tail -f and tail -F?
tail -f follows a specific open file descriptor. If the file is deleted and recreated with the same name, which happens routinely when log rotation replaces a log file, tail -f keeps watching the old, now-deleted file and stops receiving new content. tail -F (capital F) additionally watches for the file being replaced or rotated and automatically re-opens the new file by that name, making it the safer choice for long-running log monitoring on a system using logrotate.
How do I control how many lines tail shows?
Use -n followed by a number, such as tail -n 50 file.log to show the last 50 lines instead of the default 10. A useful variant is tail -n +N, which shows every line starting from line N to the end of the file, rather than counting backward from the end.
Can I follow multiple log files at the same time with tail?
Yes, list multiple files as arguments with -f, such as tail -f /var/log/nginx/access.log /var/log/nginx/error.log, and tail interleaves new lines from both files as they arrive, labeling each line with a header showing which file it came from whenever the source switches.