Linux getent Command: Query Users, Groups, and Other NSS Databases
getent queries entries in databases for accounts, groups, hosts, etc., which are used by the Name Service Switch (NSS). It is useful when you want to check not only local files but also external authentication or name services configured on the system using the same query path.
What is the getent command?
It follows the lookup order specified in /etc/nsswitch.conf, so the results may differ from simply reading the /etc/passwd file. Specify the database name first, followed by the necessary key. If the key is omitted, it will attempt enumeration, but full enumeration is not possible in all databases.
Basic syntax
getent database [key...]
Installed implementations and options may differ depending on the distribution. Check the description for your current system using man getent.
Examples
Querying user accounts
Search for users in local files or NSS-configured sources.
getent passwd alice
Querying group information
Check group names and members.
getent group editors
Check Hostname
Query the name through the NSS settings of the current system.
getent hosts localhost
Reading NSS Database Query Results
getent passwd username can look up not only the local /etc/passwd but also accounts provided through the system's NSS (Name Service Switch) configuration.
getent passwd root
Example output (home directory and shell vary by system):
root:x:0:0:root:/root:/bin/bash
In the colon-separated fields, the third is the UID, and the fourth is the primary GID. x does not display the actual password. If there is no result, the account may not exist or the NSS backend may be unavailable. A getent query is not the same as looking only in /etc/passwd.
Main Options and Format
| Options/Format | Description |
|---|---|
passwd |
Query the user account database. |
group |
Query the group database. |
hosts |
Query the host name and address database. |
-s service |
Specify the lookup service of a particular database in the glibc implementation. |
Precautions when using
Even if an account is not in /etc/passwd, it may exist in external NSS sources such as LDAP. Conversely, a getent failure can indicate either a service issue or a missing key, so check both the exit status and NSS settings together. Enumerating all keys may not be supported in some databases or may produce a large output.
Frequently Asked Questions
What is the difference between `getent passwd alice` and `grep alice /etc/passwd`?
`getent` uses the configured NSS lookup path, while `grep` only searches the text in the local file. If there is an external user directory, the results may differ.
Official Documentation
The exact behavior of options and differences by implementation can be found in the official getent documentation.









