Key facts
- Plain text, usually one timestamped entry per line; the format depends on the program (Apache combined log, PHP error log, JSON lines and so on).
- Usually served as text/plain; files can grow from a few KB to many GB if not rotated.
- Tools like logrotate rename and compress old logs as error.log.1, error.log.2.gz and so on.
- Common Linux locations are /var/log/apache2/, /var/log/nginx/ and /var/log/php*-fpm.log; WordPress writes wp-content/debug.log when WP_DEBUG_LOG is on.
- Logs often contain IP addresses, emails, tokens and file paths, so treat them as sensitive.
How to open a .log file
Small logs open in Notepad or VS Code. For large or live logs, run Get-Content .\app.log -Tail 100 -Wait in PowerShell.
Open it with the built-in Console app or a code editor, or run tail -f app.log in Terminal to follow new lines.
Run tail -n 100 -f /var/log/nginx/error.log to follow it, less +G app.log to browse from the end, and zless or zgrep for rotated .gz logs.
Common problems and fixes
- Log file is too large to open
- Editors load the whole file into memory. Read it with less, tail or grep instead, and set up logrotate or the framework's daily log setting to keep it small.
- Log is empty or not being written
- The process lacks write permission, logging is disabled, or it writes somewhere else. Check the configured path (such as error_log in php.ini or WP_DEBUG_LOG) and the file's owner and permissions.
- "Permission denied" when reading /var/log
- System logs are readable only by root or the adm group. Use sudo, or add your user to the adm group on Debian and Ubuntu.
- Old entries are missing
- They were rotated into .1 or .gz files or deleted by a retention policy. Look for app.log.1 and app.log.*.gz in the same folder and read them with zless.
- Disk is full because of logs
- Do not delete a log a process still has open, because the space is not released until it closes. Truncate it with : > app.log or sudo truncate -s 0 app.log, then fix the rotation.
Often converted to or from: CSV, JSON, TXT