Read Zstandard Files Safely with zstdless
You will open one or more Zstandard-compressed files in less without creating an uncompressed copy. Allow about five minutes. You need the zstd package, a terminal, and a readable .zst file. The examples below match the installed zstd 1.5.7 command, while the local manual page identifies its documented interface as zstd 1.5.5.
The route
Jump straight to the step you need, or tick off Done means at the end.
Checkpoint
This guide only reads and decompresses data for display. It does not alter the compressed files, services or system configuration.
1. Confirm the wrapper and its dependency
Check that both the viewer and the decompressor are available:
$ command -v zstdless
/home/linuxbrew/.linuxbrew/bin/zstdless
$ zstd --version
*** Zstandard CLI (64-bit) v1.5.7, by Yann Collet ***
Your paths and version can differ. The important detail is that zstdless is a small wrapper around less. Its installed script sets LESSOPEN to run zstd -cdfq for files that less opens, then passes your arguments to less.
If command -v zstdless prints nothing, install the distribution's zstd package using its normal package manager. That is an administrative action and is outside this viewing workflow.
2. Open one compressed file
Give the compressed path as the file argument:
$ zstdless /path/to/application.log.zst
You are now in the ordinary less interface. Use its usual navigation, such as Space for the next page, b for the previous page and q to quit. The decompressed text is produced for the pager; no replacement .log file is written.
To verify the input without opening it interactively, ask zstd to test the frame:
$ zstd -t /path/to/application.log.zst
/path/to/application.log.zst: 1 stream
$ printf '%s\n' "$?"
0
The exact test output can vary with the installed release. A zero status is the useful result. A non-zero status means the file is damaged, truncated, not a Zstandard frame, or otherwise could not be tested.
3. View several files in sequence
The synopsis accepts multiple file arguments. Pass them together when you want to move between related compressed logs in one pager session:
$ zstdless /var/log/myapp/app-2026-09-27.log.zst \
/var/log/myapp/app-2026-09-28.log.zst
Use the less commands :n and :p to move to the next and previous input file. The shell line continuation is only for readability; remove the backslash if you put the command on one line.
Common trap: options after the command are sent to less, not to zstd. For example, -N asks less to show line numbers. Do not append decompressor options to zstdless and assume the wrapper will pass them to zstd. The installed script deliberately has no separate zstd flag mechanism.
4. Read compressed data from standard input
With no file argument, zstdless reads standard input. This is useful when another command produces a Zstandard stream:
$ zstd -q -c /path/to/application.log | zstdless
In this example, zstd -c writes compressed data to standard output and zstdless presents the decompressed text. The first command is only a demonstration of a pipeline. For an existing compressed file, use zstdless /path/to/file.zst directly.
For a quick non-interactive check, make the pager finish after one screen:
$ printf '%s\n' 'alpha' 'beta' | zstd -q | LESS='-F -X' zstdless
alpha
beta
LESS='-F -X' is temporary for this command. -F quits when the output fits on one screen and -X leaves the output visible. Do not use that setting as a test for large files, where the pager will remain interactive.
5. Separate viewer settings from decompression
The wrapper honours the ZSTD environment variable when choosing the decompressor command. That is a compatibility hook, not a place to put an arbitrary shell pipeline. Leave it unset unless you have a specific, trusted command with compatible options:
$ env ZSTD=/usr/bin/zstd zstdless /path/to/application.log.zst
Prefer the default. An incorrect value can make every file fail to open, and an untrusted value would change which executable is run. If you set ZSTD in your shell profile and viewing breaks, remove that setting or run the command with a known path as above, then open a new shell after correcting the profile.
There is no need for sudo to view a file you can already read. If a log is root-readable only, ask the owner for an appropriate copy or access arrangement. Avoid teaching yourself to run a pager as root: pagers can execute interactive commands, and elevated viewing increases the impact of a mistake.
6. Diagnose the likely failure
- If
lessreports that it cannot open the file, check the path and read permission withls -l /path/to/file.zst. - If the display contains compressed bytes, confirm that the input is actually Zstandard data and that you did not bypass the wrapper with plain
less. - If decompression reports corruption, keep the original file. Do not overwrite it with a guessed repair or an empty output file; obtain another copy and compare checksums if one is available.
- If the viewer opens but the expected file is not present, remember that
zstdlesspasses file names toless; shell globs are expanded before the wrapper runs. Quote a path containing spaces, and check what a glob matched withprintf '%s\n' /path/to/*.zst.
Checkpoint
Quit the pager with q, then run zstd -t on the same file. That distinguishes a pager or path problem from damaged compressed data without changing the file.
Done means
- You opened the intended
.zstfile withzstdless. - You navigated it with normal
lesscommands and quit withq. - You know that wrapper arguments are pager arguments, not zstd arguments.
- You can test the compressed frame with
zstd -tand keep the original when it fails.