Linux watch Command: Run a Command Repeatedly

watch is a command that repeatedly executes a specified command at regular intervals and updates the entire terminal screen with the results. The default execution interval is 2 seconds, and you can change the interval with -n and highlight the parts that have changed from previous results with -d.

It is useful when observing continuously changing values, such as memory, disk, process, or network status, over a short period of time. To exit, you typically use q or Ctrl+c.

What is the watch command?

watch is a program included in the procps-ng toolset. It repeatedly executes the standard output and standard error of the command and displays the first screen's worth, allowing you to check the result changes without entering the same command multiple times.

At the top of the default screen, information such as the execution interval, the executed command, host, time, and termination status is displayed. If the execution results are longer than the screen, parts may be hidden, so other tools may be more suitable for tracking long logs or large amounts of output.

You can check the default behavior and current options in the watch(1) manual and the procps-ng watch manual source.

Basic Syntax and Usage

watch [option] command [command arguments...]

If you repeatedly run free -h without any options, the memory usage is updated every 2 seconds by default.

watch free -h

To run at 1-second intervals, add the -n option.

watch -n 1 free -h

The watch option should be placed before the command to be repeated. Options written after the command are usually passed to the repeated command, not to watch.

Frequently used options

Option Function Usage
-n seconds Specify the execution interval Specify a time value in seconds like watch -n 1 command.
-d Highlight the changed parts Highlights the characters that have changed compared to the previous screen.
-d=permanent Cumulative change highlighting Continues to highlight any parts that have changed at least once since the first execution.
-g Exit when output changes Can be used to wait until a file or status changes.
-e Stop updating on command error If the repeated command ends with a non-zero status, it pauses the screen and exits after a key press.
-b Beep on command error If the repeated command returns a non-zero state, it will sound the terminal bell.
-p Attempt exact start intervals Execute according to the specified interval based on the start time of the previous run.
-t Hide top title Secure a little more space to display the command results.
-c Interpret ANSI colors Display the supported colors and styles output by the repeated command.
-w Prevent line wrapping of long lines Displays lines that exceed the screen width by cutting them off instead of wrapping them to the next line.
-x Run without going through the shell Instead of sh -c, run programs directly without using shell expansion and pipes.

The options supported may vary depending on the version of procps-ng included in the distribution. You can check the options available on your current system with the following command.

watch --help
watch --version

Controlling interval and output changes

Specify the execution interval with -n

Specify a value in seconds after -n or --interval. You can also use decimals, but too short an interval can place unnecessary load on the CPU, disk, network, and target services.

watch -n 0.5 date
watch -n 5 df -h

If the interval is omitted, the default is 2 seconds. In the current procps-ng manual, a limit is applied to excessively small or large values, and it is recommended to check the specific range in the installed version.

Highlight changes with -d

-d highlights parts that have changed by comparing the current screen with the previous one. It is convenient when viewing memory, process, and network statistics that change rapidly.

watch -n 1 -d free -h

To continuously display all changed locations after the first screen, use -d=permanent if the installed version supports it.

watch -n 1 -d=permanent free -h

Exit when changes occur with -g

-g or --chgexit exits watch when the visible output on the screen changes. It can be used when waiting for file modification times or deployment task statuses to change.

watch -g -n 1 'stat -c %Y /tmp/result.txt'

If the output only changes in areas cut off by the screen range, changes may not be detected. For automation where change detection is critical, it is safer to use the exit status of the target command or dedicated monitoring tools rather than comparing screen output.

Why quotes are needed when using pipes and shell syntax

By default, watch executes the passed command through sh -c. If you want to use pipes, redirection, semicolons, variables, and wildcards as part of the repeated command, it is clearer to wrap the entire command in single quotes.

Simple commands are passed as they are

Commands without pipes or redirection can be written directly like this.

watch -n 2 ls -lh /var/log

Pipes and variables wrap the entire command

In the following example, single quotes prevent the current shell from processing the pipe first and pass the entire command to the shell that will execute it repeatedly.

watch -n 1 'ps -eo pid,comm,%cpu,%mem --sort=-%cpu | head -n 15'

Redirection or multiple commands are wrapped in the same way.

watch -n 5 'date; df -h / /var'

The -x option runs the program directly without going through the shell. This can slightly reduce execution cost and simplify argument passing, but shell features like pipes, redirection, variable expansion, and wildcards cannot be used.

watch -x -n 2 ls -lh /var/log

The general behavior of quotes can be found in the GNU Bash Quoting documentation.

Examples frequently used in practice

Items to Check Description
Memory Updates the free -h result every second and highlights the changed parts.
Disk Space Checks the usage of the root and /var file systems every 5 seconds.
CPU-Using Processes Sorts the ps results by CPU usage and shows the top entries.
Socket Summary Check the overall status of network sockets repeatedly with ss -s.
File Size Observe changes in the size of downloaded or compressed files with stat.
Service Status Repeatedly run systemctl status with --no-pager.

Memory Usage

watch -n 1 -d free -h

Disk Usage

watch -n 5 'df -h / /var'

Processes with high CPU usage

watch -n 1 'ps -eo pid,comm,%cpu,%mem --sort=-%cpu | head -n 15'

Network socket summary

watch -n 1 ss -s

File size and modification time

watch -n 1 'stat -c "%s bytes  %y" archive.tar'

Service Status

watch -n 2 'systemctl --no-pager --full status nginx'

Commands that can produce long output, like service status, may only show partially depending on the terminal size. If the purpose is continuous log tracking, a command suited for that function, such as journalctl -f -u nginx, is more appropriate.

Exact execution intervals and long-running commands

In the default behavior, after a single command execution finishes, it waits for the specified interval before starting the next execution. Using -p or --precise tries to align the next start time based on when the previous command started.

watch -p -n 10 'date; curl -fsS https://example.com/health'

If the execution time of a repeated command is longer than the specified interval, watch will not run multiple instances simultaneously but will wait for the current command to finish. For batch tasks that require exact cycles and guaranteed execution, using a systemd timer or a task scheduler is more suitable than watch.

Controlling with the keyboard

Key Action
q Exits watch. The running child command may not stop immediately.
Ctrl+c Sends an interrupt signal to exit both watch and the running task.
Space Requests command execution without waiting for the next scheduled time. If already running, it starts the next execution immediately after completion without delay.

Key actions may vary depending on the procps-ng version, so first check the current system's man watch.

Precautions when using watch

  • Preferably use for read-only check commands: Repeating commands that change state, such as delete, payment, user creation, or service restart, can lead to undesired results.
  • Avoid very short intervals: Running database queries, remote API requests, or large directory searches at very short intervals can put a load on the system or external services.
  • Check the visible range on the screen: -g and -d are affected by the output displayed in the terminal, so changes in the truncated area may not be detected.
  • Avoid interactive commands: Programs that wait for user input, such as password prompts, editors, or pagers, are not suitable for repeated execution.
  • Distinguish exit status: The success status of the basic watch does not always mean that the repeated command succeeded. If you need to respond to command errors, check options like -e in the current version.

When other tools are more suitable than watch

Purpose Suitable tools
Tracking logs being appended to a file tail -f or tail -F
Tracking systemd service logs journalctl -f -u service_name
Checking process resource usage top or htop
Scheduled repetitive tasks systemd timer or cron
Long-term metrics collection and alerts Dedicated Monitoring System

watch is suitable for a person to observe short-term changes on the terminal. If you need record keeping, notifications, and long-term analysis, you should choose a tool appropriate for that purpose.

Frequently Asked Questions

It says the watch command does not exist

watch is usually included in the procps or procps-ng package. It may not be present in minimal installation environments, so you need to install the package using the package manager of your current distribution. Check the distribution documentation for the package name and installation command.

Aliases or shell functions do not execute inside watch

Aliases and functions may only be defined in the current interactive shell, and they may not be passed to the sh -c environment that watch calls by default. For repetitive tasks, it is easier to predictably use the actual executable, an explicit command, or a separate shell script.

Command colors are not displayed

Enable ANSI color interpretation with watch -c, and set the repeated command to output color codes in non-interactive environments as well. Depending on the program, a separate option like --color=always may be necessary.

Why should commands that include pipes be enclosed in quotes?

Without quotes, the current shell may process the pipe first, causing the entire output of watch to be passed to another command. Enclosing the entire pipeline in single quotes allows watch to pass it as a single command string to the shell that will repeatedly execute it.

Summary

watch is a simple observation tool that repeatedly displays the results of a command at the default 2-second interval. You can change the interval with -n, highlight changes with -d, and exit when the output changes with -g.

Commands that include pipes and redirection should be enclosed entirely in single quotes, and the load and side effects of repeated execution on the system should be checked. You can find the purposes of other commands by task in the Linux command list.

More in This Category
Linux Tutorial / Linux Terminal and Shell Basics: Command Syntax and Finding Help

Linux Tutorial / Linux Terminal and Shell Basics: Command Syntax and Finding Help

Learn the difference between a terminal and a shell, read command syntax and output, and use Bash help tools through a short hands-on exercise.

Linux sort Command: Sort Text Lines

Linux sort Command: Sort Text Lines

Learn how to sort text lines with the Linux sort command, including practical examples, key options, and important precautions.

Linux rpm Command: Inspect RPM Packages and the Installed Database

Linux rpm Command: Inspect RPM Packages and the Installed Database

Learn how to inspect RPM Packages and the Installed Database with the Linux rpm command, including practical examples, key options, and important precautions.

Linux tr Command: Translate and Delete Characters

Linux tr Command: Translate and Delete Characters

Learn how to translate and Delete Characters with the Linux tr command, including practical examples, key options, and important precautions.

Linux Tutorial / Standard Input, Output, Redirection, and Pipes

Linux Tutorial / Standard Input, Output, Redirection, and Pipes

Understand standard input, output, and error; practice file redirection and pipes; and learn why overwrite risk and redirection order matter.

Linux tar Command: Create and Extract Archives

Linux tar Command: Create and Extract Archives

Learn how to create and Extract Archives with the Linux tar command, including practical examples, key options, and important precautions.

Linux du Command: Check File and Directory Disk Usage

Linux du Command: Check File and Directory Disk Usage

Learn how to use the Linux du command to measure and summarize disk space used by files and directories, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux pgrep Command: Find Process IDs by Name or Criteria

Linux pgrep Command: Find Process IDs by Name or Criteria

Learn how to find Process IDs by Name or Criteria with the Linux pgrep command, including practical examples, key options, and important precautions.

Linux w Command: Show Logged-In Users and Their Processes

Linux w Command: Show Logged-In Users and Their Processes

Learn how to show Logged-In Users and Their Processes with the Linux w command, including practical examples, key options, and important precautions.

Linux Tutorial / What Is Linux? Understanding the Kernel, Distributions, and Open Source

Linux Tutorial / What Is Linux? Understanding the Kernel, Distributions, and Open Source

Understand how the Linux kernel differs from a distribution, what user space and open source mean, and how to check your system's kernel and distribution versions.