Capture Command Output Reliably with logsave
By the end of this guide, you will be able to run a command while seeing its output normally and keeping a timestamped copy in a logfile. You will also know how to append a later run, record data from standard input, and recognise the cases where logsave has not written a file yet.
The route
Jump straight to the step you need, or tick off Done means at the end.
This guide covers the logsave 1.47.0 implementation installed by the local logsave package, from E2fsprogs 1.47.0. Allow about 10 minutes. You need a shell and write access to the directory where the log will live. The examples use /tmp, so they do not need elevated privileges.
1. Check the installed command
Confirm which executable will run and record its package version. This matters because the examples describe the installed E2fsprogs behaviour, not an assumed version from another distribution.
command -v logsave
dpkg-query -W -f='${Package} ${Version}\n' logsave
On the machine used for this guide, the result identifies /usr/sbin/logsave and package version 1.47.0-2.4~exp1ubuntu4.1. The command accepts only the documented -a, -s and -v options. It does not provide a general --help or --version option.
2. Save a command's output
Give logsave the logfile first, followed by the program and its arguments. It runs the program, copies the program's output to its own standard output, and writes a structured record to the logfile.
logsave /tmp/date.log date -u
The terminal shows the date produced by date. The logfile also contains a header naming the command, a timestamp, the command output, and a separator. Inspect it with:
sed -n '1,20p' /tmp/date.log
A typical record looks like this, although the timestamp will differ:
Log of date -u
Thu Sep 24 22:21:09 2026
Thu Sep 24 22:21:09 UTC 2026
Thu Sep 24 22:21:09 2026
----------------
Use a real command in place of date -u. Keep the logfile path separate from the command arguments so that a typo cannot turn the intended command into an argument to logsave.
Checkpoint: verify the first capture
- The command output appeared on your terminal.
/tmp/date.logexists and contains aLog ofheader.- The logfile is readable by the account that ran logsave.
3. Append a later run
Without an option, logsave replaces the logfile's previous contents. That is a destructive overwrite of the old record, so do not use the default form when the earlier run must be retained. Use -a to append a new record:
logsave -a /tmp/date.log date -u
Verify that the file now contains more than one Log of header:
grep -c '^Log of ' /tmp/date.log
The count should be 2 after exactly the two examples above. If you overwrote a record accidentally and have no backup, logsave has no undo operation. Re-run the command with -a for future records, or restore the file from your normal backup.
4. Capture standard input instead of running a program
Use a single hyphen as the command name when the data is already arriving on standard input. This is useful for saving a pipeline's final stream without inventing a temporary command.
printf '%s\n' 'health check passed' | logsave /tmp/health.log -
The text is copied to the terminal and saved in /tmp/health.log. Check the saved content with:
grep -F -- 'health check passed' /tmp/health.log
For a continuing stream, logsave must receive the stream's end before it can finish its record. If the producer does not close its output, the command can appear to hang because it is still waiting for input.
5. Handle progress-control text
Some programs redraw progress information using control characters. With -s, text bracketed by control-A and control-B is shown on the terminal but omitted from the logfile. This keeps transient progress text out of a persistent record.
printf 'start\001temporary progress\002finished\n' | logsave -s /tmp/progress.log -
Verify the result with a command that displays control characters visibly:
sed -n l /tmp/progress.log
The saved line contains startfinished, not the bracketed progress text. Choose this option only when that text is genuinely disposable. It is not a general redaction feature: it removes the marked section from the logfile, and the control-A and control-B markers must be present.
6. Deal with a missing log directory
If the directory containing the logfile does not exist, logsave keeps output in memory while the command runs. It can write the record later if the directory becomes available. This behaviour is useful during early boot, when a filesystem such as /var may not yet be mounted.
Do not treat a missing file during the run as proof that logging succeeded. A long-running command can consume significant memory if its output cannot be written, and a failed or interrupted process may leave no usable logfile. Before a routine job starts, create and permission its log directory using the service's normal deployment procedure, then check the result after logsave exits.
Creating a system log directory or writing under /var/log normally requires elevated privileges. Keep the command itself unprivileged where possible, and grant only the needed directory permission. Do not make a logfile world-writable merely to avoid a permissions error.
7. Use verbose mode only while diagnosing
The -v option makes logsave more verbose in its output to the user. It does not change the basic logfile purpose. Add it temporarily when investigating command or path handling:
logsave -v /tmp/diagnostic.log sh -c 'printf "%s\n" diagnostic'
Remove -v from unattended jobs once the problem is understood, so their console or service output remains predictable.
Done means
- You can name a logfile followed by a command and its arguments.
- You have verified that output reaches both the terminal and the logfile.
- You use
-awhen earlier records must remain intact. - You know that
-captures standard input and-somits marked progress text. - You check the log after execution, especially when its parent directory might not exist.