Follow and Colour a Log File with ctail

You will finish with a live, coloured view of a log file and a clear way to tell whether the viewer is working or merely missing its colouriser. ctail is installed here from byobu package version 6.11-0ubuntu1.1. Allow about ten minutes if ccze is already installed, or longer if your package manager needs to install it.

You need a shell, a readable log file and permission to read it. The normal viewing commands are unprivileged. Installing the missing dependency changes system packages and normally requires elevated privileges, so do that only through your usual package-management process.

1. Check the installed command

Confirm which executable will run and record the package version before troubleshooting a different copy from your PATH:

$ command -v ctail
/usr/bin/ctail
$ dpkg-query -W -f='${Package} ${Version}\n' byobu
byobu 6.11-0ubuntu1.1

The installed manual describes ctail [FILE] as a command that watches and colourises one file. The script behind that interface is also useful context: it runs tail -F and sends the stream to ccze -A. That means ctail is a small wrapper, not a separate log parser with its own configuration format.

Checkpoint: If command -v ctail prints nothing, stop here and repair the installation or PATH before testing a log.

2. Check the colouriser dependency

Run this read-only check:

$ command -v ccze
/usr/bin/ccze

Your path will differ. On this machine, ccze is not installed. In that state, ctail does not fall back to plain tail; it prints an error and exits:

$ ctail /path/to/application.log
ERROR: ccze not found, hint...
  sudo apt-get install ccze

If you administer this Debian or Ubuntu system and have decided that installing the package is appropriate, the command suggested by the installed script is:

$ sudo apt-get install ccze

This is the only command in the main workflow that normally needs sudo. Review the package transaction before accepting it. If you cannot install packages, use tail -F /path/to/application.log for an uncoloured view instead. Do not treat missing colour as evidence that the log file itself is broken.

3. Follow a test log without changing it

Use a real log path in place of /path/to/application.log. The command reads the file and follows future changes; it does not truncate, rotate or edit it:

$ ctail /path/to/application.log

Existing lines should appear first, followed by new lines as the application writes them. The exact colours depend on ccze and on the log text. The terminal may display escape sequences as colour; redirecting this interactive stream to a file is usually unhelpful because those control characters are then stored as data.

For a safe smoke test, create a disposable file in a working directory and write two ordinary log lines to it:

$ printf '%s\n' '2026-09-22 12:00:00 demo: started' '2026-09-22 12:00:01 demo: warning' > /tmp/ctail-demo.log
$ ctail /tmp/ctail-demo.log

If ccze is available, both lines should appear and the command should remain attached to the terminal, waiting for more input. The redirection above creates or replaces only the disposable file. Do not substitute a production log path on the right-hand side of >: shell redirection truncates its destination before the command runs.

Checkpoint: While ctail is running, append a line from a second terminal and watch for it:

$ printf '%s\n' '2026-09-22 12:00:02 demo: still running' >> /tmp/ctail-demo.log

The double greater-than operator appends. It does not replace the file.

4. Stop it and understand log rotation

Press Ctrl-C in the terminal running ctail. That stops the viewer and its pipeline. It does not stop the application that owns the log, and it does not undo lines already written.

The wrapper uses tail -F, rather than plain tail -f. GNU tail -F keeps following the named path when a rotated log is replaced, which is useful for ordinary rename-and-create rotation. It still cannot guarantee that every logging design is followed correctly. Copy-truncate rotation, remote filesystems and applications that keep writing to an already-unlinked inode can produce different results.

After a rotation, check that new lines are arriving from the expected file and application. If the view looks stale, stop with Ctrl-C, inspect the path and inode, then start ctail again. Restarting this viewer is safe; deleting or truncating a log to make it look fresh is a separate, potentially destructive action.

5. Diagnose the common failures

A missing file or unreadable path is different from a missing ccze. Check the target without changing it:

$ ls -l /path/to/application.log
$ test -r /path/to/application.log && echo readable

If the file is protected, do not make it world-readable merely to view it. First decide whether your account should have access. If policy permits, run the viewer with the smallest necessary privilege and remember that everything displayed in the terminal may contain secrets, tokens or personal data. A better operational fix is often to grant the correct group read access or use an approved log-access tool, rather than routinely running interactive monitoring as root.

If ctail prints the ccze error even though you believe it is installed, compare the shell paths:

$ command -v ccze
$ printf '%s\n' "$PATH"
$ dpkg-query -W -f='${Package} ${Version}\n' ccze

A different shell, service account or restricted PATH can see a different installation. Fix the environment or use the package's normal executable path; do not edit /usr/bin/ctail as a workaround.

Done means