DEV Community

Cover image for PowerShell Get-Content: Tail the Last Lines of Any Log
arnostorg
arnostorg

Posted on

PowerShell Get-Content: Tail the Last Lines of Any Log

The PowerShell Get-Content cmdlet reads text from a file. For day-to-day ops you rarely need the whole file — you need the last few lines of a growing log, a quick head sample, or a live follow while something writes. That is what -Tail, -TotalCount, and -Wait are for.

For the official reference, see Microsoft Learn’s Get-Content.

Read a file (quick refresher)

Get-Content -Path .\app.log
Enter fullscreen mode Exit fullscreen mode

By default you get an array of lines (one string per line). That is great for piping into Where-Object or Select-String. The short alias works the same way:

gc .\app.log
Enter fullscreen mode Exit fullscreen mode

Tail the last N lines with -Tail

When a log is huge, do not load the whole thing. Ask for the end:

Get-Content -Path .\app.log -Tail 20
Enter fullscreen mode Exit fullscreen mode

That prints the last 20 lines — the PowerShell equivalent of tail -n 20 on Linux. Useful right after a deploy or when an error just flashed in the console:

Get-Content -Path C:\Apps\MyService\app.log -Tail 50
Get-Content -Path .\logs\error.log -Tail 100
Enter fullscreen mode Exit fullscreen mode

Alias form:

gc .\app.log -Tail 20
Enter fullscreen mode Exit fullscreen mode

First lines with -TotalCount (head)

-TotalCount limits how many lines are read from the start of the file:

Get-Content -Path .\app.log -TotalCount 10
Enter fullscreen mode Exit fullscreen mode

That is your safe preview before you decide whether to open the file in an editor. Pair it with log headers, CSV headers, or config files where the important bit is near the top.

Goal Parameter
Last N lines -Tail N
First N lines -TotalCount N
Whole file (small files only) (omit both)

Older scripts sometimes used Get-Content file \| Select-Object -Last 20. Prefer -Tail — it is clearer and avoids streaming the entire file through the pipeline just to keep the end.

Live follow with -Wait

-Wait keeps the cmdlet open and prints new lines as they are appended — like tail -f:

Get-Content -Path .\app.log -Wait
Enter fullscreen mode Exit fullscreen mode

Combine with -Tail so you see recent context first, then stream live updates:

Get-Content -Path .\app.log -Tail 30 -Wait
Enter fullscreen mode Exit fullscreen mode

Leave that running in one PowerShell window while you restart a service or reproduce a bug in another. Press Ctrl+C when you are done.

# Watch a service log during a restart
Get-Content -Path C:\Apps\MyService\app.log -Tail 40 -Wait
Enter fullscreen mode Exit fullscreen mode

-Raw vs line array

Default Get-Content returns lines. Add -Raw when you need one big string (regex across the whole file, or a single JSON blob):

# array of lines — good for filtering
Get-Content .\app.log | Where-Object { $_ -match 'ERROR' }

# one string — good for whole-file regex / JSON
$all = Get-Content .\config.json -Raw
Enter fullscreen mode Exit fullscreen mode

Do not use -Raw on multi-gigabyte logs. You will pull the entire file into memory.

Common mistake: reading huge files whole

This looks innocent and can freeze your session on a multi-GB log:

# Bad idea on a huge log
$lines = Get-Content .\huge.log
$lines[-20..-1]
Enter fullscreen mode Exit fullscreen mode

Prefer the dedicated parameter:

# Good — reads only what you need from the end
Get-Content .\huge.log -Tail 20
Enter fullscreen mode Exit fullscreen mode

Same idea for “just show me the header”:

Get-Content .\huge.log -TotalCount 5
Enter fullscreen mode Exit fullscreen mode

Practical ops examples

Latest errors from an app log:

Get-Content .\app.log -Tail 200 |
  Where-Object { $_ -match 'ERROR|FATAL|Exception' }
Enter fullscreen mode Exit fullscreen mode

Confirm a write just landed:

Add-Content -Path .\health.log -Value "ping $(Get-Date -Format o)"
Get-Content -Path .\health.log -Tail 3
Enter fullscreen mode Exit fullscreen mode

Follow a text export that mimics Event-style lines:

Get-Content -Path .\exports\events.txt -Tail 25 -Wait
Enter fullscreen mode Exit fullscreen mode

Sample then decide:

Get-Content .\app.log -TotalCount 5   # header / format check
Get-Content .\app.log -Tail 5         # freshest activity
Enter fullscreen mode Exit fullscreen mode

Quick checklist

  • Need the end of a log → Get-Content -Tail N
  • Need a head preview → Get-Content -TotalCount N
  • Need live updates → add -Wait (often with -Tail)
  • Need one string → -Raw (small files only)
  • Never assign a giant log to a variable “just to slice the end”

Practice it live

CMD Master is a free online interactive learning platform for the command line. Practice PowerShell Get-Content in a live browser terminal with instant feedback — no install or VM. Most lessons are free; premium unlocks deeper paths.

Top comments (0)