Linux df Command Cheat Sheet: Check Disk Space and Inodes Before Your Logs Stop
Picture a 2 a.m. page: the SIEM shows a Linux server that stopped forwarding logs an hour ago. Nobody attacked it and no malware is involved. The /var/log partition simply hit 100%, and the logging services had nowhere left to write. For a SOC analyst, that is a blind spot, and a blind spot is exactly where real incidents hide. This scenario is illustrative, but anyone who has run Linux server monitoring at scale has seen some version of it.
The fastest way to catch this is a command that ships on virtually every Linux system: df. This guide turns the df cheat sheet into a practitioner's toolkit covering the commands, how to read the output, and how defenders use it for disk space monitoring, log retention, and incident response.
Table of Contents
- What df Actually Does
- Core df Commands Every Analyst Should Know
- Checking Specific Paths and Mount Points
- Inode Exhaustion: When Space Is Free but Writes Fail
- Custom Output with --output
- Why Disk Space Matters for SIEM Log Retention
- Reports, Pipelines, and Monitoring
- When df and du Disagree
- Expert Tips
- FAQ
- Conclusion
What df Actually Does
The name stands for "disk free." It queries each mounted filesystem and reports total size, used space, available space, and the mount point. It reads filesystem-level metadata, so it returns almost instantly even on huge volumes.
That is the key difference from du, which walks directories and adds up file sizes. Use df to ask "how full is this filesystem?" and du to ask "what is filling it?"
df
What it does: lists all mounted filesystems with sizes in 1K blocks by default.
When to use it: a quick sanity check. The raw numbers are hard to scan, which is why almost everyone adds -h.
Expected output: columns for Filesystem, 1K-blocks, Used, Available, Use%, and Mounted on.
Core df Commands Every Analyst Should Know
Human-readable output
df -h
Converts sizes to KB, MB, GB, and so on. This is the command you will type most. Scan the Use% column first and investigate anything above roughly 85 to 90 percent.
Add the filesystem type
df -hT
Adds a Type column (ext4, xfs, tmpfs, nfs, and so on). During an investigation, this tells you at a glance whether a path is on a real disk, in memory, or on a network share.
Show all, or only local, filesystems
df -a
df -l
-a includes pseudo and special filesystems that are normally hidden. -l limits output to local filesystems and skips network mounts. That is useful when a hung NFS share would otherwise make df stall.
POSIX-compatible format
df -P
Forces a stable, one-line-per-filesystem layout. Long device names will not wrap onto a second line, which makes it the safer choice inside scripts.
Quick reference table
| Command | Purpose |
| df -h | Human-readable disk usage |
| df -hT | Readable usage plus filesystem type |
| df -i / df -ih | Inode usage (raw / readable) |
| df -a | Include pseudo and special filesystems |
| df -l | Local filesystems only |
| df -P | POSIX output for scripting |
| df -hiT | Inodes, readable sizes, and type together |
| df -h --output=... | Choose exactly which columns to display |
Checking Specific Paths and Mount Points
You do not have to remember which device backs a directory. Give df any path and it reports the filesystem that contains it.
df -h /
df -h /home
df -h /var/log
df -h /tmp
df -h /opt
What it does: shows usage for the filesystem holding each path.
When to use it: /var/log is the most important one for defenders, since a full log volume means missing evidence. /tmp matters because attackers and misbehaving apps alike tend to fill it.
Compare several paths in one shot:
df -h / /home /var /tmp
If two paths show the same device, they share a filesystem and compete for the same free space.
Other targeted checks:
df /dev/sda1
df -h /media/$USER
df -h /mnt/share
df -Th /home
- df /dev/sda1 reports on that device, but only if it is currently mounted.
- df -h /media/$USER checks removable storage such as USB drives.
- df -h /mnt/share checks a mounted network share, for supported network filesystems.
Before moving large data, check the destination first:
df -h /destination/
After cleanup, run the same command again to confirm the space was actually reclaimed. If it was not, see the troubleshooting section below.
Inode Exhaustion: When Space Is Free but Writes Fail
Every file consumes an inode, which is a metadata record. A filesystem can run out of inodes while plenty of gigabytes remain free. The symptom is confusing: applications report "No space left on device," yet df -h shows room to spare.
df -i
df -ih
What it does: reports inode totals, used, free, and IUse% instead of block usage. The -h flag shortens large counts, such as 1.2M.
When to use it: any time writes fail but capacity looks fine. Typical culprits are directories packed with millions of tiny files, such as mail queues, session files, or runaway cache folders.
Check both views together:
df -h; df -ih
To see which top-level directory holds the most files on a filesystem (read-only, safe to run):
for d in /var/*; do echo "$d: $(find "$d" -xdev -type f 2>/dev/null | wc -l)"; done
The -xdev flag keeps find on a single filesystem so it does not wander into other mounts.
Custom Output with --output
GNU df can print only the columns you choose, which is ideal for clean reports and dashboards.
df -h --output=source
df -h --output=source,size
df -h --output=source,avail
df -h --output=source,used
df -h --output=source,pcent
df -h --output=source,size,used,avail,pcent,target
The last command produces the full picture: device, total size, used, available, percent used, and mount point. Available fields include source, fstype, itotal, iused, iavail, ipcent, size, used, avail, pcent, file, and target.
Heads-up: --output is a GNU coreutils feature, so it may be missing on minimal systems such as BusyBox. It also cannot be combined with -T, -i, or -P on GNU df. If you want inode data in this format, use the inode fields (itotal, iused, iavail, ipcent) inside --output instead.
Why Disk Space Matters for SIEM Log Retention
Security teams usually think about disk space as an operations problem. It is also a detection problem, for three reasons.
- Logs are evidence. If the volume holding authentication logs, audit records, or application logs fills up, new events may be dropped or never written. Compliance programs that require log retention can be affected as well.
- Auditing can react to a full disk. The Linux audit daemon has configurable actions for low-space and disk-full conditions, set in auditd.conf. Depending on configuration, it can suspend logging or even halt the system. Review those settings so you know what your servers will do.
- Sudden growth is a signal. A filesystem that jumps in usage can point to log flooding, a brute-force storm, a runaway process, or unexpected data staging. df will not tell you which one, but it tells you when to start asking.
In incident response, a baseline helps. If you know /var normally sits near 40 percent, a jump to 90 percent overnight is worth a ticket. Pair that with your SIEM's alerting so a quiet log source gets investigated instead of assumed healthy.
Reports, Pipelines, and Monitoring
Save a disk usage report
df -h > disk-usage.txt
Writes the current report to a file. Note that a single > overwrites the file each time.
Append to a running log
df -h >> disk-usage.log
Appends the current output to the end of the log. Combine it with a timestamp to build a simple trend history:
(date; df -h) >> disk-usage.log
Filter with grep
df -h | grep '^/dev/'
Shows only device-backed filesystems and hides tmpfs and similar entries.
Watch usage live
watch -n 5 df -h
Refreshes every 5 seconds. This is handy while a large copy, backup, or log-heavy test is running. Press Ctrl+C to exit.
Find the filesystem behind a path
df -P /var/log | tail -1
Prints just the data line for the filesystem containing /var/log, which is easy to parse in scripts.
A simple threshold check
df -hP | awk 'NR>1 && $5+0 >= 85 {print $6 " is at " $5}'
What it does: prints any mount point at 85 percent used or higher.
When to use it: as a quick manual check, or as the core of a cron job that sends an alert. For production, a proper monitoring agent with alerting is more reliable than a hand-rolled script.
When df and du Disagree
A classic puzzle: you delete a huge log file, but df still shows the disk as full. The usual cause is that a running process still has the deleted file open. The name is gone, but the space is not released until the process closes it or restarts.
List open files that have been deleted:
sudo lsof +L1
What it does: shows open files with a link count below one, meaning deleted but still held open.
What to do: identify the owning process and restart it cleanly through its service manager. Do not kill processes blindly on production systems, and avoid truncating or removing log files without confirming your retention and evidence-handling requirements first.
Other reasons the numbers differ include reserved filesystem blocks (ext filesystems reserve a percentage for root), files hidden underneath a mount point, and snapshots or copy-on-write behavior on some filesystems.
To find what is consuming space once df tells you where to look:
sudo du -xh /var/log --max-depth=1 | sort -h
This lists the size of each subdirectory under /var/log, smallest to largest, staying on one filesystem.
Expert Tips
- Check inodes whenever "No space left on device" does not match df -h. It is one of the most overlooked causes.
- Give log volumes their own partition. A separate /var/log or /var/log/audit limits the blast radius when something floods it.
- Use -l during incidents. A stalled network mount can make plain df hang at the worst moment.
- Use -P in scripts. Wrapped lines break parsers.
- Trend, do not just snapshot. A filesystem at 70 percent that grows 5 percent per day is more urgent than one steady at 85.
- Treat quiet log sources as suspicious. Missing logs deserve the same attention as noisy ones.
- Make log rotation and retention explicit. Verify rotation is working and that retention matches your policy and any frameworks you follow, such as NIST guidance or your internal compliance requirements.
Related Cybersecurity Topics You Should Explore
- Linux Disk Commands Cheat Sheet: df, du, mount, fsck (2026)
- Linux umask Cheat Sheet: 022 vs 027 vs 077 Explained
- Linux chgrp Cheat Sheet (2026): Commands, Examples & Audit Tips
- Linux chown Command Cheat Sheet: 40+ Examples (2026)
- Linux chmod Cheat Sheet: Stop Using 777 (Safer Fixes)
- OnePlus 15 Root Exploit: Zero-Permission Apps Can Take Full Control
- One Misconfigured chmod Command Gave Attackers Root Access
- How SOC Analysts Use sed to Catch Attacks Before the SIEM Does
- Linux tr Command Tutorial: Fix Messy SOC Logs in Seconds
FAQ
What is the difference between df and du?
df reports usage for entire filesystems using filesystem metadata. du measures the size of files and directories by walking them. Use df to find the full volume and du to find what is filling it.
What does df -h do?
It prints disk usage in human-readable units (KB, MB, GB) instead of raw 1K blocks, using powers of 1024. A related option, -H, uses powers of 1000.
Why does df show 100% when I deleted files?
A process likely still holds the deleted file open. Check with lsof +L1 and restart the owning service safely. Reserved blocks and files hidden beneath mount points can also cause mismatches.
How do I check inode usage?
Run df -i, or df -ih for readable counts. Watch the IUse% column. If it nears 100%, new files cannot be created even when free space remains.
Can I see only certain columns?
Yes, on GNU df, use --output with a comma-separated list such as source,size,used,avail,pcent,target. It cannot be combined with -T, -i, or -P.
Why is df slow or hanging?
An unresponsive network filesystem is the usual cause. Try df -l to limit output to local filesystems.
Does df work on network shares?
Yes, for supported network filesystems, run df -h against the mount point, such as /mnt/share. Results depend on what the remote server reports.
Conclusion
df is a small command with outsized value. A few habits go a long way: run df -h and df -ih together, keep a close eye on /var/log, compare against a baseline, and use --output or -P when you automate. Teams that treat free space as part of their detection posture catch quiet failures before they turn into missing evidence.
Add these commands to your runbooks, wire the threshold check into your monitoring, and make sure a full disk becomes an alert instead of a surprise.
Analysis based on SOC monitoring experience and review of GNU coreutils documentation.
