The PowerShell Get-Content cmdlet reads text from a file. For day-to-day ops you rarely need the whole file — you need the last few lines of a growing log, a quick head sample, or a live follow while something writes. That is what -Tail, -TotalCount, and -Wait are for.
For the official reference, see Microsoft Learn’s Get-Content.
Read a file (quick refresher)
Get-Content -Path .\app.log
By default you get an array of lines (one string per line). That is great for piping into Where-Object or Select-String. The short alias works the same way:
gc .\app.log
Tail the last N lines with -Tail
When a log is huge, do not load the whole thing. Ask for the end:
Get-Content -Path .\app.log -Tail 20
That prints the last 20 lines — the PowerShell equivalent of tail -n 20 on Linux. Useful right after a deploy or when an error just flashed in the console:
Get-Content -Path C:\Apps\MyService\app.log -Tail 50
Get-Content -Path .\logs\error.log -Tail 100
Alias form:
gc .\app.log -Tail 20
First lines with -TotalCount (head)
-TotalCount limits how many lines are read from the start of the file:
Get-Content -Path .\app.log -TotalCount 10
That is your safe preview before you decide whether to open the file in an editor. Pair it with log headers, CSV headers, or config files where the important bit is near the top.
| Goal | Parameter |
|---|---|
| Last N lines | -Tail N |
| First N lines | -TotalCount N |
| Whole file (small files only) | (omit both) |
Older scripts sometimes used Get-Content file \| Select-Object -Last 20. Prefer -Tail — it is clearer and avoids streaming the entire file through the pipeline just to keep the end.
Live follow with -Wait
-Wait keeps the cmdlet open and prints new lines as they are appended — like tail -f:
Get-Content -Path .\app.log -Wait
Combine with -Tail so you see recent context first, then stream live updates:
Get-Content -Path .\app.log -Tail 30 -Wait
Leave that running in one PowerShell window while you restart a service or reproduce a bug in another. Press Ctrl+C when you are done.
# Watch a service log during a restart
Get-Content -Path C:\Apps\MyService\app.log -Tail 40 -Wait
-Raw vs line array
Default Get-Content returns lines. Add -Raw when you need one big string (regex across the whole file, or a single JSON blob):
# array of lines — good for filtering
Get-Content .\app.log | Where-Object { $_ -match 'ERROR' }
# one string — good for whole-file regex / JSON
$all = Get-Content .\config.json -Raw
Do not use -Raw on multi-gigabyte logs. You will pull the entire file into memory.
Common mistake: reading huge files whole
This looks innocent and can freeze your session on a multi-GB log:
# Bad idea on a huge log
$lines = Get-Content .\huge.log
$lines[-20..-1]
Prefer the dedicated parameter:
# Good — reads only what you need from the end
Get-Content .\huge.log -Tail 20
Same idea for “just show me the header”:
Get-Content .\huge.log -TotalCount 5
Practical ops examples
Latest errors from an app log:
Get-Content .\app.log -Tail 200 |
Where-Object { $_ -match 'ERROR|FATAL|Exception' }
Confirm a write just landed:
Add-Content -Path .\health.log -Value "ping $(Get-Date -Format o)"
Get-Content -Path .\health.log -Tail 3
Follow a text export that mimics Event-style lines:
Get-Content -Path .\exports\events.txt -Tail 25 -Wait
Sample then decide:
Get-Content .\app.log -TotalCount 5 # header / format check
Get-Content .\app.log -Tail 5 # freshest activity
Quick checklist
- Need the end of a log →
Get-Content -Tail N - Need a head preview →
Get-Content -TotalCount N - Need live updates → add
-Wait(often with-Tail) - Need one string →
-Raw(small files only) - Never assign a giant log to a variable “just to slice the end”
Practice it live
CMD Master is a free online interactive learning platform for the command line. Practice PowerShell Get-Content in a live browser terminal with instant feedback — no install or VM. Most lessons are free; premium unlocks deeper paths.
Top comments (0)