Loading date…
LinkedIn Twitter Instagram YouTube WhatsApp
Malwarebytes - Cybersecurity for Everyone

Linux df Command Cheat Sheet: Fix Full Disk & Missing Logs

Linux terminal showing df -h output with disk usage by filesystem and a nearly full /var/log partition highlighted

Linux df Command Cheat Sheet: Check Disk Space and Inodes Before Your Logs Stop

Picture a 2 a.m. page: the SIEM shows a Linux server that stopped forwarding logs an hour ago. Nobody attacked it and no malware is involved. The /var/log partition simply hit 100%, and the logging services had nowhere left to write. For a SOC analyst, that is a blind spot, and a blind spot is exactly where real incidents hide. This scenario is illustrative, but anyone who has run Linux server monitoring at scale has seen some version of it.

The fastest way to catch this is a command that ships on virtually every Linux system: df. This guide turns the df cheat sheet into a practitioner's toolkit covering the commands, how to read the output, and how defenders use it for disk space monitoring, log retention, and incident response.

Table of Contents

What df Actually Does

The name stands for "disk free." It queries each mounted filesystem and reports total size, used space, available space, and the mount point. It reads filesystem-level metadata, so it returns almost instantly even on huge volumes.

That is the key difference from du, which walks directories and adds up file sizes. Use df to ask "how full is this filesystem?" and du to ask "what is filling it?"

df

What it does: lists all mounted filesystems with sizes in 1K blocks by default.
When to use it: a quick sanity check. The raw numbers are hard to scan, which is why almost everyone adds -h.
Expected output: columns for Filesystem, 1K-blocks, Used, Available, Use%, and Mounted on.

Core df Commands Every Analyst Should Know

Human-readable output

df -h

Converts sizes to KB, MB, GB, and so on. This is the command you will type most. Scan the Use% column first and investigate anything above roughly 85 to 90 percent.

Add the filesystem type

df -hT

Adds a Type column (ext4, xfs, tmpfs, nfs, and so on). During an investigation, this tells you at a glance whether a path is on a real disk, in memory, or on a network share.

Show all, or only local, filesystems

df -a
df -l

-a includes pseudo and special filesystems that are normally hidden. -l limits output to local filesystems and skips network mounts. That is useful when a hung NFS share would otherwise make df stall.

POSIX-compatible format

df -P

Forces a stable, one-line-per-filesystem layout. Long device names will not wrap onto a second line, which makes it the safer choice inside scripts.

Quick reference table

CommandPurpose
df -hHuman-readable disk usage
df -hTReadable usage plus filesystem type
df -i / df -ihInode usage (raw / readable)
df -aInclude pseudo and special filesystems
df -lLocal filesystems only
df -PPOSIX output for scripting
df -hiTInodes, readable sizes, and type together
df -h --output=...Choose exactly which columns to display

Checking Specific Paths and Mount Points

You do not have to remember which device backs a directory. Give df any path and it reports the filesystem that contains it.

df -h /
df -h /home
df -h /var/log
df -h /tmp
df -h /opt

What it does: shows usage for the filesystem holding each path.
When to use it: /var/log is the most important one for defenders, since a full log volume means missing evidence. /tmp matters because attackers and misbehaving apps alike tend to fill it.

Compare several paths in one shot:

df -h / /home /var /tmp

If two paths show the same device, they share a filesystem and compete for the same free space.

Other targeted checks:

df /dev/sda1
df -h /media/$USER
df -h /mnt/share
df -Th /home
  • df /dev/sda1 reports on that device, but only if it is currently mounted.
  • df -h /media/$USER checks removable storage such as USB drives.
  • df -h /mnt/share checks a mounted network share, for supported network filesystems.

Before moving large data, check the destination first:

df -h /destination/

After cleanup, run the same command again to confirm the space was actually reclaimed. If it was not, see the troubleshooting section below.

Inode Exhaustion: When Space Is Free but Writes Fail

Every file consumes an inode, which is a metadata record. A filesystem can run out of inodes while plenty of gigabytes remain free. The symptom is confusing: applications report "No space left on device," yet df -h shows room to spare.

df -i
df -ih

What it does: reports inode totals, used, free, and IUse% instead of block usage. The -h flag shortens large counts, such as 1.2M.
When to use it: any time writes fail but capacity looks fine. Typical culprits are directories packed with millions of tiny files, such as mail queues, session files, or runaway cache folders.

Check both views together:

df -h; df -ih

To see which top-level directory holds the most files on a filesystem (read-only, safe to run):

for d in /var/*; do echo "$d: $(find "$d" -xdev -type f 2>/dev/null | wc -l)"; done

The -xdev flag keeps find on a single filesystem so it does not wander into other mounts.

Custom Output with --output

GNU df can print only the columns you choose, which is ideal for clean reports and dashboards.

df -h --output=source
df -h --output=source,size
df -h --output=source,avail
df -h --output=source,used
df -h --output=source,pcent
df -h --output=source,size,used,avail,pcent,target

The last command produces the full picture: device, total size, used, available, percent used, and mount point. Available fields include source, fstype, itotal, iused, iavail, ipcent, size, used, avail, pcent, file, and target.

Heads-up: --output is a GNU coreutils feature, so it may be missing on minimal systems such as BusyBox. It also cannot be combined with -T, -i, or -P on GNU df. If you want inode data in this format, use the inode fields (itotal, iused, iavail, ipcent) inside --output instead.

Why Disk Space Matters for SIEM Log Retention

Security teams usually think about disk space as an operations problem. It is also a detection problem, for three reasons.

  • Logs are evidence. If the volume holding authentication logs, audit records, or application logs fills up, new events may be dropped or never written. Compliance programs that require log retention can be affected as well.
  • Auditing can react to a full disk. The Linux audit daemon has configurable actions for low-space and disk-full conditions, set in auditd.conf. Depending on configuration, it can suspend logging or even halt the system. Review those settings so you know what your servers will do.
  • Sudden growth is a signal. A filesystem that jumps in usage can point to log flooding, a brute-force storm, a runaway process, or unexpected data staging. df will not tell you which one, but it tells you when to start asking.

In incident response, a baseline helps. If you know /var normally sits near 40 percent, a jump to 90 percent overnight is worth a ticket. Pair that with your SIEM's alerting so a quiet log source gets investigated instead of assumed healthy.

Reports, Pipelines, and Monitoring

Save a disk usage report

df -h > disk-usage.txt

Writes the current report to a file. Note that a single > overwrites the file each time.

Append to a running log

df -h >> disk-usage.log

Appends the current output to the end of the log. Combine it with a timestamp to build a simple trend history:

(date; df -h) >> disk-usage.log

Filter with grep

df -h | grep '^/dev/'

Shows only device-backed filesystems and hides tmpfs and similar entries.

Watch usage live

watch -n 5 df -h

Refreshes every 5 seconds. This is handy while a large copy, backup, or log-heavy test is running. Press Ctrl+C to exit.

Find the filesystem behind a path

df -P /var/log | tail -1

Prints just the data line for the filesystem containing /var/log, which is easy to parse in scripts.

A simple threshold check

df -hP | awk 'NR>1 && $5+0 >= 85 {print $6 " is at " $5}'

What it does: prints any mount point at 85 percent used or higher.
When to use it: as a quick manual check, or as the core of a cron job that sends an alert. For production, a proper monitoring agent with alerting is more reliable than a hand-rolled script.

When df and du Disagree

A classic puzzle: you delete a huge log file, but df still shows the disk as full. The usual cause is that a running process still has the deleted file open. The name is gone, but the space is not released until the process closes it or restarts.

List open files that have been deleted:

sudo lsof +L1

What it does: shows open files with a link count below one, meaning deleted but still held open.
What to do: identify the owning process and restart it cleanly through its service manager. Do not kill processes blindly on production systems, and avoid truncating or removing log files without confirming your retention and evidence-handling requirements first.

Other reasons the numbers differ include reserved filesystem blocks (ext filesystems reserve a percentage for root), files hidden underneath a mount point, and snapshots or copy-on-write behavior on some filesystems.

To find what is consuming space once df tells you where to look:

sudo du -xh /var/log --max-depth=1 | sort -h

This lists the size of each subdirectory under /var/log, smallest to largest, staying on one filesystem.

Expert Tips

  • Check inodes whenever "No space left on device" does not match df -h. It is one of the most overlooked causes.
  • Give log volumes their own partition. A separate /var/log or /var/log/audit limits the blast radius when something floods it.
  • Use -l during incidents. A stalled network mount can make plain df hang at the worst moment.
  • Use -P in scripts. Wrapped lines break parsers.
  • Trend, do not just snapshot. A filesystem at 70 percent that grows 5 percent per day is more urgent than one steady at 85.
  • Treat quiet log sources as suspicious. Missing logs deserve the same attention as noisy ones.
  • Make log rotation and retention explicit. Verify rotation is working and that retention matches your policy and any frameworks you follow, such as NIST guidance or your internal compliance requirements.

FAQ

What is the difference between df and du?

df reports usage for entire filesystems using filesystem metadata. du measures the size of files and directories by walking them. Use df to find the full volume and du to find what is filling it.

What does df -h do?

It prints disk usage in human-readable units (KB, MB, GB) instead of raw 1K blocks, using powers of 1024. A related option, -H, uses powers of 1000.

Why does df show 100% when I deleted files?

A process likely still holds the deleted file open. Check with lsof +L1 and restart the owning service safely. Reserved blocks and files hidden beneath mount points can also cause mismatches.

How do I check inode usage?

Run df -i, or df -ih for readable counts. Watch the IUse% column. If it nears 100%, new files cannot be created even when free space remains.

Can I see only certain columns?

Yes, on GNU df, use --output with a comma-separated list such as source,size,used,avail,pcent,target. It cannot be combined with -T, -i, or -P.

Why is df slow or hanging?

An unresponsive network filesystem is the usual cause. Try df -l to limit output to local filesystems.

Does df work on network shares?

Yes, for supported network filesystems, run df -h against the mount point, such as /mnt/share. Results depend on what the remote server reports.

Conclusion

df is a small command with outsized value. A few habits go a long way: run df -h and df -ih together, keep a close eye on /var/log, compare against a baseline, and use --output or -P when you automate. Teams that treat free space as part of their detection posture catch quiet failures before they turn into missing evidence.

Add these commands to your runbooks, wire the threshold check into your monitoring, and make sure a full disk becomes an alert instead of a surprise.

Analysis based on SOC monitoring experience and review of GNU coreutils documentation.

Shubham Chaudhary

Shubham Chaudhary is a cybersecurity specialist and founder of Xpert4Cyber. He shares practical tutorials, guides and the latest news on Networking, Windows Server, Linux Server, Ethical Hacking, Digital Forensics, Malware Analysis, Threat Hunting and Monitoring, OSINT, Cloud Computing and AI, with a focus on defense and security awareness. Educational and defensive use only.

Post a Comment

Previous Post Next Post