zless pages through a gzip-compressed file as though it were plain text, with no second uncompressed copy left behind on disk. That matters when all you need is ten lines from a log that already ends in .gz. The examples use zless from gzip 1.12, installed here as package version 1.12-1ubuntu3.2, with GNU less 590.
Allow about ten minutes. You need a shell, the gzip package and a terminal with a pager. This guide only reads files. It does not edit, delete, decompress or replace them, and it normally needs no elevated privileges.
zless is really just less with a decompression step wired in front of it, so start by pinning down which build of each you have:
$ command -v zless
/usr/bin/zless
$ zless --version
zless (gzip) 1.12
Copyright (C) 2007, 2011-2018 Free Software Foundation, Inc.
The exact copyright lines can differ between package builds. The useful checkpoint is that the command exists and reports the gzip version you expect.
Pass the path to a gzip-compressed file as an argument:
$ zless /path/to/application.log.gz
zless starts less and arranges for gzip to feed it the uncompressed contents. The compressed file stays in place. You can move through the text with the normal less controls, search with /pattern, and leave the pager with q.
Do not confuse viewing with extraction. The command does not create application.log beside the archive. If you need a separate uncompressed copy, use a deliberate decompression command and check the destination before writing it; that is a different workflow.
Checkpoint: Press q. Your shell prompt should return, and the original archive should still exist:
$ test -r /path/to/application.log.gz && echo 'archive is still readable'
archive is still readable
The manpage describes zless as handling compressed or plain text. You can therefore use the same entry point when a log may or may not have a .gz suffix:
$ zless /path/to/application.log
This is useful in a small diagnostic script or a manual investigation where the storage format is not worth remembering. The filename extension is not a command option, and renaming a file does not compress it.
Keep the input path as a separate, quoted shell argument when it contains spaces or shell characters:
$ zless '/path/to/Logs from Tuesday.log.gz'
The synopsis accepts one or more names. Pass files in the order you want to visit them:
$ zless /var/log/service.log.2.gz /var/log/service.log.1.gz /var/log/service.log
The pager presents the arguments as a file list. This lets you move between rotated logs without manually decompressing each one. Use an explicit list when the order matters; an unquoted shell glob such as /var/log/service.log.* is expanded by the shell, and its ordering and membership depend on the directory contents.
Reading a system log is ordinarily unprivileged if your account has read access. If a path is protected, first check it without changing permissions:
$ ls -l /var/log/service.log.1.gz
$ test -r /var/log/service.log.1.gz && echo readable || echo 'not readable by this account'
Use sudo only if your host's access policy permits it and you have a specific reason to read that file. Do not change log permissions just to make a viewing command convenient.
There is a deliberate boundary that catches people: this installed zless does not work with compressed data arriving on standard input. The command requires input files as arguments.
This will not perform the intended operation:
$ cat /path/to/application.log.gz | zless
For compressed data already in a pipe, follow the documented alternative and send the decompressed stream to less:
$ gzip -cd -- /path/to/application.log.gz | less
That pipeline also does not write a decompressed file. The -- marks the end of gzip options, which keeps a filename beginning with a hyphen from being interpreted as another option. A pipeline can hide the decompressor's status on some shell configurations, so when diagnosing a damaged archive, test the archive separately:
$ gzip -t -- /path/to/application.log.gz
$ printf 'gzip check status: %s\n' "$?"
gzip check status: 0
Status 0 means gzip accepted the archive test. A non-zero result means you should preserve the original and investigate the file or its transfer before relying on what a pager displays.
Use -- where the underlying gzip command accepts it, and quote paths supplied by a user or another program. Do not paste an untrusted filename into an unquoted shell command. A safe variable-based example is:
log_file='/path/to/application.log.gz'
if test -r "$log_file"; then
zless -- "$log_file"
else
printf 'Cannot read %s\n' "$log_file" >&2
exit 1
fi
The pager option set belongs to less, not to a separate zless language. If an unfamiliar option matters to your workflow, check man less on the same machine. Do not assume that a control or option from another pager has the same meaning.
If zless reports that it cannot open a file, check the path and permissions. If it reports a decompression problem, keep the archive unchanged and run gzip -t. If you need to recover a readable prefix from a damaged file, make that a separate evidence-preserving task rather than redirecting output over the only copy.
gzip -cd ... | less when compressed data is already in a pipe.