Read Compressed Text One Screen at a Time with zmore

zmore is the compressed-file cousin of the old more pager, decompressing gzip, compress or pack files as it goes. Point it at several files at once and it also names each one as you reach it, which a plain pager will not.

The examples use zmore from gzip 1.12, installed here as package version 1.12-1ubuntu3.2. Allow about ten minutes. You need a shell, a readable text file or compressed text file, and a terminal if you want the interactive pager.

No elevated privileges are needed. Do not use sudo to read a file that your account cannot access unless you have checked that the file is appropriate to disclose. A pager can expose its contents to your screen and to commands launched from its prompt.

1. Check the installed command

Pin the binary and package version down before relying on anything below; these are ordinary, read-only commands:

$ command -v zmore
/usr/bin/zmore
$ zmore --version
zmore (gzip) 1.12
Copyright (C) 2010-2018 Free Software Foundation, Inc.
$ dpkg-query -W -f='${Package} ${Version}\n' gzip
gzip 1.12-1ubuntu3.2

The local manpage describes the interface as zmore [name ...]. The installed script also accepts --help and --version. Treat those long options as version-specific checks rather than assuming that every old implementation has the same option handling.

Checkpoint: If command -v finds a different path, or the version is not 1.12, run zmore --help and read that machine's manpage before copying the interactive examples.

2. Open one plain or compressed file

Pass the file name as an argument. zmore accepts uncompressed text and files compressed with gzip, compress, or pack. For an ordinary text file:

$ zmore /path/to/application.log

It displays a screenful, then waits at a --More-- prompt. On a terminal with 24 display lines, the default window is 22 lines. The exact number can differ because zmore reads terminal information from /etc/termcap.

For gzip text, pass the compressed file directly:

$ zmore /path/to/application.log.gz

zmore does not create an extracted copy in your working directory. It decompresses the stream for viewing. That keeps the original file unchanged, but it does not make the contents safe to disclose.

Checkpoint: If you only need to prove that the file can be read, use a small sample or stop after the first screen. If the terminal fills with text, press the quit key described in the next step.

3. Control the pause prompt

Commands at the prompt take effect immediately. You do not press Return after them. The most useful keys are:

InputEffect
SpaceDisplay another screenful.
ReturnDisplay one more line.
d or Ctrl-DDisplay 11 more lines, or set the scroll size when prefixed by a number.
q or QQuit.
=Show the current line number.
20zDisplay another screenful and make the window 20 lines.
20sSkip 20 lines, then display a screenful.
20fSkip 20 screenfuls, then display a screenful.

To interrupt output that is already being sent to the terminal, use the quit key, normally Ctrl-\. zmore then returns to its prompt. The manpage warns that some output may already be lost because waiting terminal output is flushed by that signal.

4. Search without extracting the file

At --More--, enter a slash, a regular expression, and its end-of-line key. For example, this searches for the first occurrence of the word timeout:

/timeout

Use 2/timeout to search for the second occurrence. The erase and kill characters edit the expression; erasing back beyond the first column cancels the search. Use n to repeat the last search, or 2n to find its second subsequent occurrence.

Search expressions are regular expressions, not fixed strings. Escape punctuation when your expression requires it. If a search appears not to match, check the spelling and the expression first, then try a shorter expression. The file remains compressed on disk throughout this operation.

5. Let zmore find a compressed suffix

If the exact name does not exist, zmore looks for the same name with .gz, .z, or .Z appended. This is useful when a script or inventory records the logical name without its compression suffix:

$ ls /var/log/example.log*
/var/log/example.log.gz
$ zmore /var/log/example.log

The lookup is not a general search. It checks the documented suffixes for that exact base name. If none exists, you will get an error from the underlying decompression command. Do not respond by guessing a different file name, especially in a directory containing logs from several services.

6. Read several files and recognise the headers

Pass multiple names when you want to compare files:

$ zmore /path/to/old.log.gz /path/to/current.log.gz

When output is going to a terminal, zmore uses the pager. When output is not a terminal, it behaves like zcat. With more than one file it prints a header around each file, for example:

::::::::::::::
/path/to/old.log.gz
::::::::::::::
first file's uncompressed text
::::::::::::::
/path/to/current.log.gz
::::::::::::::
second file's uncompressed text

The header is output, not part of either input file. This distinction matters if another command consumes the result.

7. Choose a pager or produce a plain stream

zmore normally uses the program named by PAGER, falling back to more. Set it for one invocation when you prefer less:

$ PAGER=less zmore /path/to/application.log.gz

For a non-interactive check, set PAGER=cat and redirect the result:

$ PAGER=cat zmore /path/to/application.log.gz > /tmp/application.log
$ wc -l /tmp/application.log
123 /tmp/application.log

The line count is only an example: your file will produce a different number. Inspect the output before using it. If you do not need zmore's file headers or interactive behaviour, zcat may express a pipeline more clearly, but keep zmore when you want its terminal controls and suffix lookup.

Recovery: The example writes a new file under /tmp; it does not alter the compressed input. If that temporary output is no longer needed, remove that specific file with rm -- /tmp/application.log. Check the path first. Never replace an original log with redirected output until you have verified the result and retained a backup.

8. Diagnose the common failures

A missing file usually means the name or suffix lookup did not resolve. Check it without elevated privileges:

$ ls -l /path/to/application.log /path/to/application.log.gz
ls: cannot access '/path/to/application.log': No such file or directory

A permission error means your account cannot read the selected path. Confirm the ownership and mode with ls -l, then ask the file owner for an appropriate access path. Do not add sudo to a routine log-reading command without considering who may see the data.

If output is not paged, check whether your command is being piped or redirected. zmore intentionally switches to stream-like output when standard output is not a terminal. If a pipeline hangs or produces unexpected headers, run the first command alone, then add the next stage after you have inspected a small result.

Done means