Linux du Command: Check File and Directory Disk Usage

du is a command that calculates and displays the amount of space that specified files and directories use on the filesystem. To check the size of items under the current directory in a human-readable format, use du -h --max-depth=1., and to see only the total, use du -sh..

du -h --max-depth=1 .
du -sh .

The default behavior of du is based on the actual blocks allocated on the filesystem, not the apparent size of file contents. In the case of sparse files, compressed filesystems, hard links, and Copy-on-Write environments, the numbers may differ from those produced by other tools.

What does the du command calculate?

du stands for disk usage, and it traverses file and directory trees to sum up disk usage. Because it is affected not only by file contents but also by the filesystem block allocation method, it does not always match the file size shown by ls -l.

Options and calculation limitations can be found in the GNU Coreutils du official documentation.

Most frequently used basic commands

Check the total size of the current directory

du -sh .

-s shows only the total, while -h displays in human-readable units like KiB, MiB, GiB. Hidden files and hidden directories are also included in the total of the current directory.

Check the size of individual items directly below

du -h --max-depth=1 .

--max-depth=1 displays up to one level below the starting point. In GNU du, you can also write it briefly as -d 1, but other Unix variants may or may not support this.

Find large items by sorting

du -h --max-depth=1 /var | sort -h

sort -h sorts by considering human-readable units. To display large items at the top, use sort -hr.

du -h --max-depth=1 /var | sort -hr

Directories without permission may produce errors, and the total may be incomplete. Execute with appropriate permissions only for the required scope, and do not simply hide errors and interpret the results as complete values.

Summary of major options

Option Function Usage examples
-h Display in human-readable units du -h /var/log
-s Show only the total of each argument du -sh /var/log
-a Display not only directories but also files du -ah ./data
-c Add a grand total at the end du -ch file1 file2
-d N Specify the maximum directory depth to display du -h -d 2 .
-x Do not cross to other filesystems du -xhd1 /
--exclude Exclude paths matching a pattern du -sh --exclude='*.log' .
--apparent-size Show apparent size instead of allocated space du -sh --apparent-size file

Search files and directories in detail

Display all files

du -ah ./data | sort -hr | head -n 20

Useful for quickly finding higher-level items in small directories. On large filesystems, it may use a lot of disk I/O and memory because it traverses and sorts all paths.

Display only items larger than a minimum size

du -h --threshold=1G ./data

GNU du's --threshold outputs only items larger than the specified size. It may not be supported on some distributions or other Unix implementations, so check du --help if portability is needed.

Exclude specific files or directories

du -sh --exclude='*.log' --exclude='cache' .

It is safe to enclose the pattern for --exclude in single quotes to prevent the shell from expanding it first. If there are many exclusion rules, you can create a file with one rule per line and use --exclude-from.

du -sh --exclude-from=du-exclude.txt .

The difference between actual usage and apparent size

Basic Disk Usage

The basic du sums up the blocks allocated to files by the filesystem. Even very small files can use at least the minimum block size of space, and the file's metadata or the internal structure of the filesystem may not be fully reflected in the result.

Apparent Size

--apparent-size shows a value close to the logical length of the content for regular files.

du -h sample.img
du -h --apparent-size sample.img

Sparse files can have a very large logical size but use almost no actual blocks. Conversely, in environments with filesystem compression, deduplication, snapshots, or Copy-on-Write shared blocks, the basic du may also differ from the actual consumption on the physical device.

Hard Links

If multiple paths point to the same inode as hard links, GNU du by default counts the space of the same file only once. Depending on the order in which multiple arguments are passed, the usage may be attributed to different paths. Using options that calculate each link separately may result in a total larger than the actual unique blocks.

Limiting Filesystem Boundaries

Skipping Other Mount Points

When examining the root filesystem, using -x or --one-file-system prevents descending into other filesystems.

du -xhd1 /

This option reduces the chance of unintentionally traversing network filesystems, separate data volumes, or virtual filesystems. However, usage of separate mount points is excluded from the results, so ensure it aligns with your investigation purpose.

Handling Symbolic Links

By default, du does not follow the targets of symbolic links in command-line arguments or inside directories. Options to follow links can traverse large amounts of other directories or filesystems, so check the target structure before using them.

Reasons du and df Results Differ

The calculation targets are different

du sums up the files in directories it can access, whereas df reports usage for the entire filesystem. Differences can occur due to filesystem metadata, reserved blocks, snapshots, or paths that cannot be read due to permissions.

Deleted but Open Files

If a file is deleted while a process has it open, du cannot find the file if only the path is deleted, but the blocks are not released until the process closes the file, so df still shows it as being used. You can check deleted open files as follows.

lsof +L1

Do not forcibly terminate the target process. Instead, check the normal restart of the service and log reopening procedures. Arbitrarily manipulating the file descriptor of a deleted file can cause data loss or service disruption.

How to Use Safely and Accurately

  • First, check the full filesystem with df -h, then run du within the respective mount point.
  • When investigating from the root, decide whether to exclude other filesystems using -x.
  • For large directories, conduct the investigation step by step with limited depth during low workload periods.
  • If there are permission errors, record the fact that the results are incomplete and use only the minimum necessary permissions.
  • Before deleting a file, check the owning process, backup, retention policy, and whether recovery is possible.
  • File names may contain special characters such as line breaks, so consider using a combination of tools that support NUL separation in automation.

Frequently Asked Questions

Are hidden files included in the du results?

If you specify the directory itself, like du -sh., hidden files are included in the total. However, the shell's * by default does not match hidden items, so du -sh * results may exclude them.

How can I quickly find the largest directories?

Check step by step using du -h --max-depth=1 target | sort -hr. This can reduce load and output compared to sorting all files in the entire tree at once.

Why are the sizes different between du -sh and ls -lh?

ls -lh mainly shows the logical length of files, while the default du shows the allocated filesystem blocks. Differences may occur due to sparse files, small files, and block sizes.

Is it okay to hide the 'Permission denied' error?

While it can make the screen cleaner, the fact that the results are incomplete also disappears. In capacity investigations, it is safer to first check the path where the error occurred and review the reason and scope of the required permissions.

Summary

du -sh path shows the total, and du -h --max-depth=1 path shows the usage of each item directly below. When looking for large items, combine with sort -hr, and use -x to exclude other filesystems.

The du value is an estimate affected by the filesystem structure and allocation method. If there is a difference with df, you need to check deleted open files, reserved blocks, snapshots, and permission issues.

More in This Category
Linux ssh-keygen Command: Generate SSH Keys and Inspect Fingerprints

Linux ssh-keygen Command: Generate SSH Keys and Inspect Fingerprints

Learn how to generate SSH Keys and Inspect Fingerprints with the Linux ssh-keygen command, including practical examples, key options, and important precautions.

Linux apk Command: Manage Packages on Alpine Linux

Linux apk Command: Manage Packages on Alpine Linux

Learn how to manage Packages on Alpine Linux with the Linux apk command, including practical examples, key options, and important precautions.

Linux Tutorial / Linux Terminal and Shell Basics: Command Syntax and Finding Help

Linux Tutorial / Linux Terminal and Shell Basics: Command Syntax and Finding Help

Learn the difference between a terminal and a shell, read command syntax and output, and use Bash help tools through a short hands-on exercise.

Linux comm Command: Compare Two Sorted Files

Linux comm Command: Compare Two Sorted Files

Learn how to compare Two Sorted Files with the Linux comm command, including practical examples, key options, and important precautions.

Linux gzip Command: Compress a File in gzip Format

Linux gzip Command: Compress a File in gzip Format

Learn how to compress a File in gzip Format with the Linux gzip command, including practical examples, key options, and important precautions.

Linux unxz Command: Decompress xz Files

Linux unxz Command: Decompress xz Files

Learn how to decompress xz Files with the Linux unxz command, including practical examples, key options, and important precautions.

Linux bunzip2 Command: Decompress bzip2 Files

Linux bunzip2 Command: Decompress bzip2 Files

Learn how to decompress bzip2 Files with the Linux bunzip2 command, including practical examples, key options, and important precautions.

Linux apt-get Command: Run APT Package Operations in Scripts

Linux apt-get Command: Run APT Package Operations in Scripts

Learn how to run APT Package Operations in Scripts with the Linux apt-get command, including practical examples, key options, and important precautions.

Linux nslookup Command: Query DNS Names and Records

Linux nslookup Command: Query DNS Names and Records

Learn how to query DNS Names and Records with the Linux nslookup command, including practical examples, key options, and important precautions.

Linux Tutorial / File System Basics: Paths and Key Directories

Linux Tutorial / File System Basics: Paths and Key Directories

Understand the Linux directory tree, read absolute and relative paths, and learn what common directories such as /home, /etc, and /var are used for.