Linux watch Command: Run a Command Repeatedly

watch is a command that repeatedly executes a specified command at regular intervals and updates the entire terminal screen with the results. The default execution interval is 2 seconds, and you can change the interval with -n and highlight the parts that have changed from previous results with -d.

It is useful when observing continuously changing values, such as memory, disk, process, or network status, over a short period of time. To exit, you typically use q or Ctrl+c.

What is the watch command?

watch is a program included in the procps-ng toolset. It repeatedly executes the standard output and standard error of the command and displays the first screen's worth, allowing you to check the result changes without entering the same command multiple times.

At the top of the default screen, information such as the execution interval, the executed command, host, time, and termination status is displayed. If the execution results are longer than the screen, parts may be hidden, so other tools may be more suitable for tracking long logs or large amounts of output.

You can check the default behavior and current options in the watch(1) manual and the procps-ng watch manual source.

Basic Syntax and Usage

watch [option] command [command arguments...]

If you repeatedly run free -h without any options, the memory usage is updated every 2 seconds by default.

watch free -h

To run at 1-second intervals, add the -n option.

watch -n 1 free -h

The watch option should be placed before the command to be repeated. Options written after the command are usually passed to the repeated command, not to watch.

Frequently used options

Option Function Usage
-n seconds Specify the execution interval Specify a time value in seconds like watch -n 1 command.
-d Highlight the changed parts Highlights the characters that have changed compared to the previous screen.
-d=permanent Cumulative change highlighting Continues to highlight any parts that have changed at least once since the first execution.
-g Exit when output changes Can be used to wait until a file or status changes.
-e Stop updating on command error If the repeated command ends with a non-zero status, it pauses the screen and exits after a key press.
-b Beep on command error If the repeated command returns a non-zero state, it will sound the terminal bell.
-p Attempt exact start intervals Execute according to the specified interval based on the start time of the previous run.
-t Hide top title Secure a little more space to display the command results.
-c Interpret ANSI colors Display the supported colors and styles output by the repeated command.
-w Prevent line wrapping of long lines Displays lines that exceed the screen width by cutting them off instead of wrapping them to the next line.
-x Run without going through the shell Instead of sh -c, run programs directly without using shell expansion and pipes.

The options supported may vary depending on the version of procps-ng included in the distribution. You can check the options available on your current system with the following command.

watch --help
watch --version

Controlling interval and output changes

Specify the execution interval with -n

Specify a value in seconds after -n or --interval. You can also use decimals, but too short an interval can place unnecessary load on the CPU, disk, network, and target services.

watch -n 0.5 date
watch -n 5 df -h

If the interval is omitted, the default is 2 seconds. In the current procps-ng manual, a limit is applied to excessively small or large values, and it is recommended to check the specific range in the installed version.

Highlight changes with -d

-d highlights parts that have changed by comparing the current screen with the previous one. It is convenient when viewing memory, process, and network statistics that change rapidly.

watch -n 1 -d free -h

To continuously display all changed locations after the first screen, use -d=permanent if the installed version supports it.

watch -n 1 -d=permanent free -h

Exit when changes occur with -g

-g or --chgexit exits watch when the visible output on the screen changes. It can be used when waiting for file modification times or deployment task statuses to change.

watch -g -n 1 'stat -c %Y /tmp/result.txt'

If the output only changes in areas cut off by the screen range, changes may not be detected. For automation where change detection is critical, it is safer to use the exit status of the target command or dedicated monitoring tools rather than comparing screen output.

Why quotes are needed when using pipes and shell syntax

By default, watch executes the passed command through sh -c. If you want to use pipes, redirection, semicolons, variables, and wildcards as part of the repeated command, it is clearer to wrap the entire command in single quotes.

Simple commands are passed as they are

Commands without pipes or redirection can be written directly like this.

watch -n 2 ls -lh /var/log

Pipes and variables wrap the entire command

In the following example, single quotes prevent the current shell from processing the pipe first and pass the entire command to the shell that will execute it repeatedly.

watch -n 1 'ps -eo pid,comm,%cpu,%mem --sort=-%cpu | head -n 15'

Redirection or multiple commands are wrapped in the same way.

watch -n 5 'date; df -h / /var'

The -x option runs the program directly without going through the shell. This can slightly reduce execution cost and simplify argument passing, but shell features like pipes, redirection, variable expansion, and wildcards cannot be used.

watch -x -n 2 ls -lh /var/log

The general behavior of quotes can be found in the GNU Bash Quoting documentation.

Examples frequently used in practice

Items to Check Description
Memory Updates the free -h result every second and highlights the changed parts.
Disk Space Checks the usage of the root and /var file systems every 5 seconds.
CPU-Using Processes Sorts the ps results by CPU usage and shows the top entries.
Socket Summary Check the overall status of network sockets repeatedly with ss -s.
File Size Observe changes in the size of downloaded or compressed files with stat.
Service Status Repeatedly run systemctl status with --no-pager.

Memory Usage

watch -n 1 -d free -h

Disk Usage

watch -n 5 'df -h / /var'

Processes with high CPU usage

watch -n 1 'ps -eo pid,comm,%cpu,%mem --sort=-%cpu | head -n 15'

Network socket summary

watch -n 1 ss -s

File size and modification time

watch -n 1 'stat -c "%s bytes  %y" archive.tar'

Service Status

watch -n 2 'systemctl --no-pager --full status nginx'

Commands that can produce long output, like service status, may only show partially depending on the terminal size. If the purpose is continuous log tracking, a command suited for that function, such as journalctl -f -u nginx, is more appropriate.

Exact execution intervals and long-running commands

In the default behavior, after a single command execution finishes, it waits for the specified interval before starting the next execution. Using -p or --precise tries to align the next start time based on when the previous command started.

watch -p -n 10 'date; curl -fsS https://example.com/health'

If the execution time of a repeated command is longer than the specified interval, watch will not run multiple instances simultaneously but will wait for the current command to finish. For batch tasks that require exact cycles and guaranteed execution, using a systemd timer or a task scheduler is more suitable than watch.

Controlling with the keyboard

Key Action
q Exits watch. The running child command may not stop immediately.
Ctrl+c Sends an interrupt signal to exit both watch and the running task.
Space Requests command execution without waiting for the next scheduled time. If already running, it starts the next execution immediately after completion without delay.

Key actions may vary depending on the procps-ng version, so first check the current system's man watch.

Precautions when using watch

  • Preferably use for read-only check commands: Repeating commands that change state, such as delete, payment, user creation, or service restart, can lead to undesired results.
  • Avoid very short intervals: Running database queries, remote API requests, or large directory searches at very short intervals can put a load on the system or external services.
  • Check the visible range on the screen: -g and -d are affected by the output displayed in the terminal, so changes in the truncated area may not be detected.
  • Avoid interactive commands: Programs that wait for user input, such as password prompts, editors, or pagers, are not suitable for repeated execution.
  • Distinguish exit status: The success status of the basic watch does not always mean that the repeated command succeeded. If you need to respond to command errors, check options like -e in the current version.

When other tools are more suitable than watch

Purpose Suitable tools
Tracking logs being appended to a file tail -f or tail -F
Tracking systemd service logs journalctl -f -u service_name
Checking process resource usage top or htop
Scheduled repetitive tasks systemd timer or cron
Long-term metrics collection and alerts Dedicated Monitoring System

watch is suitable for a person to observe short-term changes on the terminal. If you need record keeping, notifications, and long-term analysis, you should choose a tool appropriate for that purpose.

Frequently Asked Questions

It says the watch command does not exist

watch is usually included in the procps or procps-ng package. It may not be present in minimal installation environments, so you need to install the package using the package manager of your current distribution. Check the distribution documentation for the package name and installation command.

Aliases or shell functions do not execute inside watch

Aliases and functions may only be defined in the current interactive shell, and they may not be passed to the sh -c environment that watch calls by default. For repetitive tasks, it is easier to predictably use the actual executable, an explicit command, or a separate shell script.

Command colors are not displayed

Enable ANSI color interpretation with watch -c, and set the repeated command to output color codes in non-interactive environments as well. Depending on the program, a separate option like --color=always may be necessary.

Why should commands that include pipes be enclosed in quotes?

Without quotes, the current shell may process the pipe first, causing the entire output of watch to be passed to another command. Enclosing the entire pipeline in single quotes allows watch to pass it as a single command string to the shell that will repeatedly execute it.

Summary

watch is a simple observation tool that repeatedly displays the results of a command at the default 2-second interval. You can change the interval with -n, highlight changes with -d, and exit when the output changes with -g.

Commands that include pipes and redirection should be enclosed entirely in single quotes, and the load and side effects of repeated execution on the system should be checked. You can find the purposes of other commands by task in the Linux command list.

More in This Category
Linux zypper Command: Manage Packages on openSUSE and SUSE

Linux zypper Command: Manage Packages on openSUSE and SUSE

Learn how to manage Packages on openSUSE and SUSE with the Linux zypper command, including practical examples, key options, and important precautions.

Linux help Command: Read Help for Bash Built-in Commands

Linux help Command: Read Help for Bash Built-in Commands

Learn how to use the Linux help command to read usage information for Bash built-in commands, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux pkill Command: Signal Processes by Name

Linux pkill Command: Signal Processes by Name

Learn how to signal Processes by Name with the Linux pkill command, including practical examples, key options, and important precautions.

Linux getent Command: Query Users, Groups, and Other NSS Databases

Linux getent Command: Query Users, Groups, and Other NSS Databases

Learn how to query Users, Groups, and Other NSS Databases with the Linux getent command, including practical examples, key options, and important precautions.

Linux Tutorial / File Types and Metadata: ls, file, stat, and readlink

Linux Tutorial / File Types and Metadata: ls, file, stat, and readlink

Learn what ls, file, stat, and readlink each reveal about a Linux file, including type, size, timestamps, and symbolic-link targets.

Linux whereis Command: Locate Binaries, Source, and Man Pages

Linux whereis Command: Locate Binaries, Source, and Man Pages

Learn how Linux whereis locates binaries, source files, and manual pages, limits each search type, lists effective paths, and differs from which and find.

Linux nmap Command: Scan Authorized Hosts and Ports

Linux nmap Command: Scan Authorized Hosts and Ports

Learn how to scan Authorized Hosts and Ports with the Linux nmap command, including practical examples, key options, and important precautions.

Linux sort Command: Sort Text Lines

Linux sort Command: Sort Text Lines

Learn how to sort text lines with the Linux sort command, including practical examples, key options, and important precautions.

Linux ethtool Command: Inspect Network Link and Driver Settings

Linux ethtool Command: Inspect Network Link and Driver Settings

Learn how to inspect Network Link and Driver Settings with the Linux ethtool command, including practical examples, key options, and important precautions.

Linux unalias Command: Remove Command Aliases

Linux unalias Command: Remove Command Aliases

Learn how to use the Linux unalias command to remove one or all aliases from the current shell session, with essential options, practical examples, output interpretation, and common troubleshooting tips.