Linux dmesg Command: Read Kernel and Boot Messages
dmesg reads messages recorded in the kernel ring buffer. It helps investigate hardware detection, drivers, filesystems, and kernel warnings during boot.
What is the dmesg command?
The kernel ring buffer has a limited size, so older messages can be overwritten. The default output includes messages of different priorities and timestamps. Human-readable timestamps from -T can be inaccurate if the system clock has been adjusted; consult the journal's boot log when timing matters.
Basic syntax
dmesg [option]
Implementations and options may vary by distribution. Check your system's documentation with man dmesg.
Examples
Checking kernel messages
It outputs up to the most recent records, so if the screen is long, use a pager.
dmesg | less
Viewing only warnings and errors
Reduces the scope of investigation to error and warning levels.
dmesg --level=err,warn
Follow new messages
Check incoming kernel messages in real time. Press Ctrl+C to stop.
dmesg --follow
Reading Kernel Messages and Relative Time
The default time display of dmesg is usually based on the elapsed time since boot. After the number, messages related to hardware, drivers, or the filesystem follow.
dmesg --level=err,warn | tail -n 3
Example format (actual messages vary by system):
[ 12.345678] device: warning message
If the output is empty, there may be no messages of that level in the current ring buffer, and if you cannot read it due to permission restrictions, an error will be displayed. Since the size of the ring buffer is limited and old records may disappear, check the journal retention along with previous boot events using journalctl -k -b -1. dmesg -c clears the buffer, so it is not used for simple checks.
Main Options and Format
| Options/Format | Description |
|---|---|
--level=LIST |
Displays only messages of the specified priorities. |
-T |
Displays time in a human-readable format. |
-H |
Uses human-readable output and a pager. |
-w |
Continuously waits for new messages. |
-k |
Displays kernel messages only. |
Precautions when using
Some distributions restrict non-administrators from reading the kernel log; check the system policy if you encounter a permission error. dmesg -c and --clear clear the buffer, so do not use them for a simple query. An empty result does not prove there is no problem. If retained by the journal, you can inspect the previous boot's kernel messages with journalctl -k -b -1.
Frequently Asked Questions
dmesg and journalctl -k, are they the same?
Both allow you to check kernel messages, but dmesg reads the kernel ring buffer, whereas journalctl -k queries the kernel entries collected and stored in the journal.
Official Documentation
For exact option behavior, see the dmesg manual page.









