9 September 2026 · One command a day
How do I watch the nginx error log in real time?
The tail -f command prints the last few lines of a file and then keeps printing new lines as they arrive. Pointed at the nginx error log, it shows you what nginx is complaining about at the exact moment you reproduce a problem. You reach for it when a site returns a 502 or 500 and the page itself tells you nothing.
The command
sudo tail -f /var/log/nginx/error.log
tail shows the end of a file, ten lines by default. -f stands for follow: instead of exiting, tail waits and prints each new line as nginx writes it. /var/log/nginx/error.log is the default error log on Ubuntu. It is only readable by root and the adm group, hence sudo. Add -n 50 before the path to start with the last fifty lines instead of ten. Press Ctrl+C to stop.
What you will see
2026/09/09 10:41:12 [error] 1234#1234: *5678 connect() failed (111: Connection refused) while connecting to upstream, client: 127.0.0.1, server: example.com, request: "GET /api/health HTTP/1.1", upstream: "http://127.0.0.1:3000/api/health", host: "example.com"
2026/09/09 10:41:20 [error] 1234#1234: *5680 open() "/var/www/sitename/favicon.ico" failed (2: No such file or directory), client: 127.0.0.1, server: example.com, request: "GET /favicon.ico HTTP/1.1", host: "example.com"
Each line starts with a timestamp and a level in square brackets, usually [error], [crit] or [warn]. Then comes the worker process id and a connection number. The rest is the message, followed by which client asked, which server block handled it and what the request was. The first line above is the classic 502. Nginx tried to pass the request to an app on port 3000 and nothing was listening. The second line is a missing file, and it shows you the exact path nginx looked in.
When to use it
- A site shows 502 Bad Gateway after a deploy. Start tail, reload the page, and the upstream line tells you which port nginx expected the app on. Then check what is actually listening on that port.
- Uploads or slow requests fail with 413 or 504. The log names the size limit or timeout that was hit, so you know which directive to change before you reload nginx.
- A static file returns 404 or 403 even though it exists. The open() message shows the path and permission error nginx saw, which is often not the path you assumed.
Watch out for
Many server blocks set their own error_log, so the errors you want may be going to a separate file named after the site rather than the global log. If tail shows nothing while the site is clearly broken, run grep -r error_log /etc/nginx/sites-enabled/ to find where that site logs. Also make sure you are watching the error log and not access.log, which records every request whether it failed or not.
Questions people ask
Why does tail -f show nothing when my app returns a 500?
Nginx only logs its own problems. If the app behind it answers with a 500, nginx passes that on without comment, so look in the app's own logs instead.
Does tail -f keep working after the log is rotated?
No. After logrotate renames the file, tail -f keeps reading the old one. Use tail -F with a capital F and it will reopen the new file by name.
Reading the raw error log as it is written is something shared hosting rarely allows, but on a server you control it is one command away. You can get the same VPS with 20% off at https://asksteves.co.uk/vps. Affiliate link.
Everything on this blog runs on one Hostinger KVM 8. This link takes 20% off the same box.
Affiliate link.