Read Large Files Safely with less on Linux
You will finish with a compact workflow for opening logs and source files, finding text, following a file as it grows, and leaving the terminal in a predictable state. The examples use less 590, the version installed on this machine, from the less package. Allow about ten minutes for the basic workflow, or twenty minutes if you want to check the environment details as well.
The route
Jump straight to the step you need, or tick off Done means at the end.
You need a shell and a readable text file. No command in the main workflow needs elevated privileges. Use sudo only when the file itself requires it, and be careful: giving a pager access to a protected file also gives its interactive shell and editor commands an opportunity to run with that access.
1. Open a file and leave cleanly
Start with a file you are allowed to read:
$ less /path/to/your/file.log
less does not normally read the entire file before showing the first screen, so it starts promptly on large input. Press SPACE to move forward by a window, b to move back, and q to quit. g goes to the beginning; G goes to the end.
Checkpoint: open a small file, press G, then g, and press q. You should return to your shell prompt without changing the file.
2. Make a small file behave like a command
For scripts and quick checks, -F makes less exit when the whole file fits on one screen. -X prevents terminal initialisation and deinitialisation, which is useful when the terminal should retain its current screen:
$ less -F -X /path/to/your/short-file.txt
These options do not edit the file. If the file is longer than one screen, less remains interactive. The related -E option exits at the first end-of-file, while the default is to stay open until you press q. Use -F when the decision should depend on the file fitting on screen, and use -E when reaching the end should be enough.
You can also view command output without creating a temporary file:
$ journalctl -b --no-pager | less -F -X
The pipe is ordinary shell input. It is not a request to change the journal. On a command that may produce a great deal of output, the default pipe buffering can grow as you move through it. The -B option caps pipe buffering at 64 KiB by default, but older output may then be discarded and become unavailable while you are viewing it. Do not add -B unless that trade-off is acceptable.
3. Search without losing your place
Press /, type a pattern, and press ENTER to search forwards. Press ? to search backwards. less treats the pattern as a regular expression, so punctuation such as ., *, [ and ] can have special meaning. Press n for the next match and N for the previous match.
$ less /var/log/my-service.log
/ERROR
n
N
In this example, the leading + is not typed at the less prompt. It is a command-line instruction that starts at the first matching line:
$ less +/ERROR /var/log/my-service.log
Use -i for case-insensitive searches unless the pattern contains an uppercase letter. Use -I when case should always be ignored:
$ less -I +/timeout /var/log/my-service.log
Search highlighting can become visual noise. Press ESC, then u to toggle the highlighting off. To search for literal text rather than a regular expression, begin the search with CTRL-R, then enter the text. This is useful when a log message contains brackets or other regex punctuation.
4. Make long lines and line numbers explicit
Source files and structured logs often contain lines wider than the terminal. The default is to wrap them. Use -S to chop long lines instead, then use the left and right arrow keys to inspect the hidden part:
$ less -S /path/to/your/application.log
Chopping makes one screen row correspond to one input line, but it can hide important fields until you scroll horizontally. If you prefer the default wrapping, omit -S.
Use -N when line numbers help you report a location:
$ less -N /path/to/your/configuration.conf
Line numbering can add work for very large input. If performance matters more than displayed numbers, -n suppresses them. The command = shows file information, including the current line and byte position where available.
5. Follow a log while it grows
Open the file at its end, then press F to keep reading as new data arrives:
$ less +F /var/log/my-service.log
This is similar to tail -f. Press CTRL-C to stop waiting and return to the less prompt. You can then search, move around, or press F again. If the file is replaced during rotation, plain F continues reading the original file. In less 590, add --follow-name when you specifically want less to reopen a replacement file with the same name:
$ less --follow-name +F /var/log/my-service.log
That follows the name, not a guarantee that the replacement has the same permissions or content. Stop and check the prompt if output suddenly changes after rotation. For a process that must keep following logs unattended, use a purpose-built logging service or supervisor rather than leaving an interactive pager running.
6. Check the environment before trusting the display
less reads options from the LESS environment variable before command-line options. The command line wins, and an option can be reset with its -+ form. Check the variable when a familiar invocation behaves unexpectedly:
$ printf 'LESS=%s\n' "${LESS-}"
$ less --version
less 590 (GNU regular expressions)
Two other variables deserve attention. LESSOPEN can run an input preprocessor before a named file is displayed, and LESSCLOSE can run a postprocessor when it closes. That may be useful for compressed files, but it means opening a file can execute configured commands. Use -L or --no-lessopen to ignore LESSOPEN for files opened afterwards:
$ less --no-lessopen /path/to/your/file.log
Do not treat -L as a complete security boundary. It does not disable shell commands available inside less, and it does not remove an already-open file. If you do not trust the environment, inspect it and use a clean environment for the whole command, for example env -i PATH="$PATH" less --no-lessopen /path/to/your/file.log. Make sure the command name and file path are still the ones you intend before pressing ENTER.
7. Avoid commands that change state
less is primarily a viewer, but it can invoke an editor with v, run a shell command with !, pipe displayed input with |, and save piped input with s. Those actions can change files, run programs, disclose data or affect services. Treat them as separate, deliberate operations. Never paste untrusted log text into a shell command, and do not use -f casually: it forces less to open non-regular files such as devices and suppresses the warning for binary files.
There is no undo inside less for a command you run through ! or an editor. If you only need to inspect content, stay with navigation, search and display options. If a protected file must be read, prefer a controlled copy with appropriate permissions and remove that copy using your normal data-handling procedure when it is no longer needed.
Done means
- You can open a file, move with
SPACE,b,gandG, and quit withq. - You can search forwards and backwards, repeat a search, and recognise when a pattern is a regular expression.
- You choose
-S,-N,-For-Efor a stated display or exit requirement. - You can follow a growing log with
+F, stop withCTRL-C, and understand the file-rotation boundary. - You have checked
LESS, know thatLESSOPENcan execute a preprocessor, and avoid state-changing commands unless they are intentional.