Disk space runs out faster than you expect. Your web server stops accepting uploads, your database crashes mid-transaction, or your log files silently fail to write. Checking disk usage on Linux is a fundamental skill every server administrator, developer, and hosting customer needs to master. This guide assumes you have never worked with Linux disk commands before and walks you through everything from basic terminology to practical troubleshooting workflows.
Understanding Disk Usage Basics
Before running any commands, you need to understand what you are measuring. Linux organizes storage into filesystems—structured areas on physical disks or virtual storage devices where files live. Each filesystem is mounted at a specific directory path. For example, your root filesystem might be mounted at /, while a separate data partition could be mounted at /var/www.
When we talk about disk usage, we mean two related concepts:
- Filesystem capacity: how much total space is available on a mounted filesystem, how much is used, and how much remains free
- Directory size: how much space a specific folder and its contents consume
Linux counts disk usage in blocks—fixed-size chunks of storage—but commands typically display results in human-readable units like megabytes (MB) or gigabytes (GB).
Checking Overall Disk Space with df
The df command (disk free) shows you a high-level view of all mounted filesystems. It answers the question: which filesystems are attached to my server and how full are they?
Your First df Command
Open your terminal and run:
df -h
The -h flag means "human-readable"—it converts raw block counts into units like GB instead of displaying thousands of numbers.
You will see output similar to this:
Filesystem Size Used Avail Use% Mounted on
/dev/sda1 50G 32G 16G 67% /
/dev/sda2 100G 78G 17G 83% /var/www
tmpfs 2.0G 1.2M 2.0G 1% /run
Let's decode each column:
- Filesystem: the device name or virtual filesystem identifier
- Size: total capacity of this filesystem
- Used: how much space is currently occupied
- Avail: how much free space remains (not simply Size minus Used, because filesystems reserve space for the root user)
- Use%: percentage of capacity consumed
- Mounted on: where this filesystem appears in your directory tree
What to Look For
A filesystem at 90% or higher is a warning sign. Linux systems behave unpredictably when disk space drops below 10%. Database servers may refuse to start, logs stop writing, and temporary file operations fail.
Pay special attention to:
/(root): contains system files, configuration, and usually/var/log/var: often holds databases, website files, and logs/home: user files and home directories/tmp: temporary files (usually cleared on reboot)
Filtering Specific Filesystems
If you only care about your web root directory:
df -h /var/www
This shows just the filesystem containing that path.
To exclude temporary or virtual filesystems and see only real disk storage:
df -h -x tmpfs -x devtmpfs
Finding What Uses Space with du
The du command (disk usage) measures how much space directories and files consume. While df gives you the big picture, du helps you drill down and find the culprit when a filesystem fills up.
Basic du Syntax
To check the size of a directory:
du -h /var/www
This will list every subdirectory inside /var/www with its size. The output can be overwhelming for directories with thousands of files.
Summarizing Directory Size
Add the -s flag (summarize) to show only the total:
du -sh /var/www
Output:
45G /var/www
Now you know the entire directory consumes 45 gigabytes.
Finding the Largest Subdirectories
To see which subdirectories use the most space, limit the depth with --max-depth:
du -h --max-depth=1 /var/www | sort -hr
Breaking this down:
du -h --max-depth=1 /var/www: show sizes for/var/wwwand its immediate children only| sort -hr: pipe the output tosort, using-hto handle human-readable sizes and-rto reverse the order (largest first)
Output:
45G /var/www
30G /var/www/uploads
10G /var/www/backups
5G /var/www/logs
Now you can see that /var/www/uploads is your biggest directory.
Checking Specific File Types
To find all log files in a directory and see their total size:
du -ch /var/log/*.log | tail -1
The -c flag produces a grand total, and tail -1 shows only that final line.
Listing the Biggest Files
Sometimes a single file balloons out of control. The find command combined with sorting helps locate these files.
find /var/www -type f -exec du -h {} + | sort -hr | head -20
This command:
- Finds all files (
-type f) under/var/www - Runs
du -hon each file to get its size - Sorts the results largest-first
- Shows the top 20
You might discover a 15 GB error log or a forgotten database dump consuming precious space.
Using ncdu for Interactive Exploration
ncdu (NCurses Disk Usage) is a text-based interactive tool that makes exploring disk usage easier. It is not installed by default on most systems.
Installing ncdu
On Debian or Ubuntu:
sudo apt update && sudo apt install ncdu
On CentOS, Rocky Linux, or AlmaLinux:
sudo yum install ncdu
Running ncdu
ncdu /var/www
The tool scans the directory, then presents a navigable list sorted by size. Use arrow keys to move up and down, press Enter to dive into a subdirectory, and press d to delete files (use this carefully). Press q to quit.
ncdu is especially helpful when you need to interactively explore unfamiliar directory structures without memorizing du flags.
Practical Workflows for Common Scenarios
Scenario 1: Your Server Is Running Out of Space
- Check which filesystem is full:
bash df -h - Identify the mount point (e.g.,
/varis at 95%) - Find the largest directories:
bash du -h --max-depth=2 /var | sort -hr | head -10 - Investigate the biggest offender (e.g.,
/var/log) - Examine individual files:
bash ls -lh /var/log | sort -k5 -hr | head -10 - Clean up as appropriate—rotate logs, delete old backups, clear caches
Scenario 2: Finding Hidden Space Hogs
Files deleted by applications but still held open by running processes do not free space until the process restarts. To find these:
lsof | grep deleted
Restart the offending service to reclaim the space.
Scenario 3: Monitoring a Filesystem Over Time
Create a simple monitoring script:
#!/bin/bash
df -h / | tail -1 | awk '{print $5}' | sed 's/%//' > /tmp/disk_usage.txt
USAGE=$(cat /tmp/disk_usage.txt)
if [ $USAGE -gt 85 ]; then
echo "Warning: Disk usage is at ${USAGE}%" | mail -s "Disk Alert" [email protected]
fi
Save this as disk_check.sh, make it executable (chmod +x disk_check.sh), and schedule it with cron to run daily.
Understanding Inode Usage
Linux filesystems have a second limit beyond space: inodes. An inode is a data structure that stores metadata about a file. Even if you have free space, you can run out of inodes if you create millions of tiny files.
Check inode usage:
df -i
Output:
Filesystem Inodes IUsed IFree IUse% Mounted on
/dev/sda1 3276800 298456 2978344 9% /
If IUse% approaches 100%, you have too many files. Common culprits include:
- Email queue directories with thousands of stuck messages
- Session directories in web applications
- Cache directories that grow indefinitely
To find directories with the most files:
for dir in /var/*; do echo "$dir: $(find "$dir" -type f 2>/dev/null | wc -l)"; done | sort -t: -k2 -nr | head -10
Preventing Disk Space Problems
Log Rotation
Ensure logrotate is configured for all application logs. Check /etc/logrotate.conf and /etc/logrotate.d/ for rotation rules. Logs should compress after rotation and delete after a sensible retention period.
Database Maintenance
Databases grow indefinitely without maintenance. MySQL and MariaDB tables accumulate overhead; PostgreSQL requires regular vacuuming. Schedule regular optimization and consider binary log rotation policies.
Backup Cleanup
Automated backup scripts should delete old backups. If you keep daily backups, retain seven days on local disk and older backups on remote storage.
Monitoring Alerts
Set up automated monitoring with tools like Nagios, Zabbix, or simple cron scripts that email you when disk usage crosses a threshold. Catching problems at 80% is better than discovering them at 100%.
Common Mistakes to Avoid
Deleting files while applications are writing to them: Always stop or restart the service first, especially with logs.
Forgetting about hidden files: Use du -sh .[^.]* * to include hidden directories when scanning your home directory.
Not checking all filesystems: df without arguments shows everything; do not assume / is your only filesystem.
Ignoring kernel cache: The kernel uses free RAM as disk cache. free -h might show low "available" memory, but this is normal and not a disk space issue.
Running du on network filesystems: Scanning NFS or CIFS mounts can be extremely slow. Use -x with du to stay on the local filesystem.
Conclusion
Checking disk usage on Linux starts with two commands: df to see filesystem capacity and du to measure directory sizes. Master these tools and you will spot storage problems before they crash your server. Always investigate sudden spikes in usage—they usually point to runaway logs, forgotten backups, or application bugs. Set up monitoring, establish log rotation policies, and make disk checks part of your regular maintenance routine. Your servers will thank you with better uptime and fewer emergency late-night scrambles.
