Before you cat a multi-gigabyte log to "just take a quick look", reach for head instead: it prints the first 10 lines by default and stops there. By the end you will know when to select lines, when to select bytes, how to handle several files at once, and how to avoid accidental output changes in scripts.
Prerequisites: a Linux shell and GNU coreutils. The command used for these examples is coreutils 9.4. Nothing here needs elevated privileges unless the file you choose is not readable by your account. Allow about five minutes, plus time to pick a harmless test file.
Confirm which implementation you are using first. The options and suffixes below describe GNU head, not an unspecified Unix variant.
$ head --version | head -n 1
head (GNU coreutils) 9.4
For repeatable output, create a temporary file in /tmp. This changes state, but only to create a disposable file; remove it when you finish.
test_file=$(mktemp)
printf '%s\n' alpha bravo charlie delta echo foxtrot > "$test_file"
head "$test_file"
rm -- "$test_file"
Expect the six lines you wrote. A file with fewer than 10 lines prints in full: the default is a maximum, not a promise of exactly 10 lines.
Checkpoint: if you are following along, recreate the temporary file before the next step, because the cleanup command above just removed it.
Use -n when a line is the unit that matters. The long form reads better in a script:
$ printf '%s\n' one two three four five | head --lines=3
one
two
three
The short form is head -n 3. A bare numeric option such as head -3 still works on this GNU version for compatibility, but the explicit option says what you meant and will not get confused with another argument later.
There is a second line-count mode people miss constantly: a leading hyphen means all but the last count of lines.
$ printf '%s\n' one two three four five | head --lines=-2
one
two
three
Still a preview, not an edit: the input file is untouched. If it has fewer lines than the excluded count, the result is simply empty.
Use -c or --bytes for a byte count. This matters for binary data, fixed-size records, and pipelines where a newline has no special meaning.
$ printf 'abcdefghij' | head --bytes=4
abcd$
The shell prompt lands on the same line because the input had no trailing newline. That is expected: head does not add one just to tidy up your terminal.
As with lines, a negative count keeps everything except the final count of bytes:
$ printf 'abcdefghij' | head --bytes=-3
abcdefg
kB means 1,000 bytes; K and KiB mean 1,024. head -c 4K file.bin selects 4,096 bytes.With no file operand, or a file operand of -, head reads standard input, which is what makes it useful at the start of a pipeline.
$ printf '%s\n' first second third fourth | head -n 2
first
second
$ printf '%s\n' first second third | head -n 1 -- -
first
The -- in the second command ends option processing, and the trailing - names standard input explicitly. It is not required there, but it removes any ambiguity once a script grows more arguments.
Do not lean on head as proof that a command completed successfully. A producer can fail after writing just enough data for head to exit happily, and pipeline exit-status rules depend on the shell. Check the producer separately when that status actually matters.
Hand it more than one file and GNU head prints a header naming each one before its selected content.
$ printf 'red\nblue\n' > /tmp/head-one
$ printf 'green\nyellow\n' > /tmp/head-two
$ head -n 1 /tmp/head-one /tmp/head-two
==> /tmp/head-one <==
red
==> /tmp/head-two <==
green
-q or --quiet when those headers would corrupt a machine-readable stream.-v or --verbose when you want a header even for a single file.These two files are disposable examples. Remove them once you have checked the output:
$ rm -- /tmp/head-one /tmp/head-two
That rm is the only destructive command in this guide. Check the paths before you press Return, and never swap them for a broad wildcard while you are experimenting.
Most text uses newline delimiters, but tools that handle arbitrary file names often use NUL bytes instead. -z or --zero-terminated tells head to treat NUL as the record delimiter rather than newline.
$ printf 'one\0two\0three\0' | head -z -n 2 | od -An -t x1
6f 6e 65 00 74 77 6f 00
The two records and their terminating NUL bytes survive intact. Without -z, that same stream has no newline at all, so line selection would treat it as one long line. Carry the option through the rest of the pipeline whenever the next command also expects NUL records.
-- before it, as in head -n 5 -- --notes.txt.-n or -c with the count attached or given as its argument.For a final, harmless check, confirm the installed command still reports the release you expect:
$ head --version | sed -n '1p'
head (GNU coreutils) 9.4
-n and the first bytes with -c.-z.-q.