Home / Alt manpages / less(1)

  • less(1)
  • User command
  • linux

Read Large Files Safely with less on Linux

You will finish with a compact workflow for opening logs and source files, finding text, following a file as it grows, and leaving the terminal in a predictable state. The examples use less 590, the version installed on this machine, from the less package. Allow about ten minutes for the basic workflow, or twenty minutes if you want to check the environment details as well.

You need a shell and a readable text file. No command in the main workflow needs elevated privileges. Use sudo only when the file itself requires it, and be careful: giving a pager access to a protected file also gives its interactive shell and editor commands an opportunity to run with that access.

1. Open a file and leave cleanly

Start with a file you are allowed to read:

$ less /path/to/your/file.log

less does not normally read the entire file before showing the first screen, so it starts promptly on large input. Press SPACE to move forward by a window, b to move back, and q to quit. g goes to the beginning; G goes to the end.

Checkpoint: open a small file, press G, then g, and press q. You should return to your shell prompt without changing the file.

2. Make a small file behave like a command

For scripts and quick checks, -F makes less exit when the whole file fits on one screen. -X prevents terminal initialisation and deinitialisation, which is useful when the terminal should retain its current screen:

$ less -F -X /path/to/your/short-file.txt

These options do not edit the file. If the file is longer than one screen, less remains interactive. The related -E option exits at the first end-of-file, while the default is to stay open until you press q. Use -F when the decision should depend on the file fitting on screen, and use -E when reaching the end should be enough.

You can also view command output without creating a temporary file:

$ journalctl -b --no-pager | less -F -X

The pipe is ordinary shell input. It is not a request to change the journal. On a command that may produce a great deal of output, the default pipe buffering can grow as you move through it. The -B option caps pipe buffering at 64 KiB by default, but older output may then be discarded and become unavailable while you are viewing it. Do not add -B unless that trade-off is acceptable.

3. Search without losing your place

Press /, type a pattern, and press ENTER to search forwards. Press ? to search backwards. less treats the pattern as a regular expression, so punctuation such as ., *, [ and ] can have special meaning. Press n for the next match and N for the previous match.

$ less /var/log/my-service.log
/ERROR
n
N

In this example, the leading + is not typed at the less prompt. It is a command-line instruction that starts at the first matching line:

$ less +/ERROR /var/log/my-service.log

Use -i for case-insensitive searches unless the pattern contains an uppercase letter. Use -I when case should always be ignored:

$ less -I +/timeout /var/log/my-service.log

Search highlighting can become visual noise. Press ESC, then u to toggle the highlighting off. To search for literal text rather than a regular expression, begin the search with CTRL-R, then enter the text. This is useful when a log message contains brackets or other regex punctuation.

4. Make long lines and line numbers explicit

Source files and structured logs often contain lines wider than the terminal. The default is to wrap them. Use -S to chop long lines instead, then use the left and right arrow keys to inspect the hidden part:

$ less -S /path/to/your/application.log

Chopping makes one screen row correspond to one input line, but it can hide important fields until you scroll horizontally. If you prefer the default wrapping, omit -S.

Use -N when line numbers help you report a location:

$ less -N /path/to/your/configuration.conf

Line numbering can add work for very large input. If performance matters more than displayed numbers, -n suppresses them. The command = shows file information, including the current line and byte position where available.

5. Follow a log while it grows

Open the file at its end, then press F to keep reading as new data arrives:

$ less +F /var/log/my-service.log

This is similar to tail -f. Press CTRL-C to stop waiting and return to the less prompt. You can then search, move around, or press F again. If the file is replaced during rotation, plain F continues reading the original file. In less 590, add --follow-name when you specifically want less to reopen a replacement file with the same name:

$ less --follow-name +F /var/log/my-service.log

That follows the name, not a guarantee that the replacement has the same permissions or content. Stop and check the prompt if output suddenly changes after rotation. For a process that must keep following logs unattended, use a purpose-built logging service or supervisor rather than leaving an interactive pager running.

6. Check the environment before trusting the display

less reads options from the LESS environment variable before command-line options. The command line wins, and an option can be reset with its -+ form. Check the variable when a familiar invocation behaves unexpectedly:

$ printf 'LESS=%s\n' "${LESS-}"
$ less --version
less 590 (GNU regular expressions)

Two other variables deserve attention. LESSOPEN can run an input preprocessor before a named file is displayed, and LESSCLOSE can run a postprocessor when it closes. That may be useful for compressed files, but it means opening a file can execute configured commands. Use -L or --no-lessopen to ignore LESSOPEN for files opened afterwards:

$ less --no-lessopen /path/to/your/file.log

Do not treat -L as a complete security boundary. It does not disable shell commands available inside less, and it does not remove an already-open file. If you do not trust the environment, inspect it and use a clean environment for the whole command, for example env -i PATH="$PATH" less --no-lessopen /path/to/your/file.log. Make sure the command name and file path are still the ones you intend before pressing ENTER.

7. Avoid commands that change state

less is primarily a viewer, but it can invoke an editor with v, run a shell command with !, pipe displayed input with |, and save piped input with s. Those actions can change files, run programs, disclose data or affect services. Treat them as separate, deliberate operations. Never paste untrusted log text into a shell command, and do not use -f casually: it forces less to open non-regular files such as devices and suppresses the warning for binary files.

There is no undo inside less for a command you run through ! or an editor. If you only need to inspect content, stay with navigation, search and display options. If a protected file must be read, prefer a controlled copy with appropriate permissions and remove that copy using your normal data-handling procedure when it is no longer needed.

Done means

  • You can open a file, move with SPACE, b, g and G, and quit with q.
  • You can search forwards and backwards, repeat a search, and recognise when a pattern is a regular expression.
  • You choose -S, -N, -F or -E for a stated display or exit requirement.
  • You can follow a growing log with +F, stop with CTRL-C, and understand the file-rotation boundary.
  • You have checked LESS, know that LESSOPEN can execute a preprocessor, and avoid state-changing commands unless they are intentional.