Linux watch Command: Run a Command Repeatedly

watch is a command that repeatedly executes a specified command at regular intervals and updates the entire terminal screen with the results. The default execution interval is 2 seconds, and you can change the interval with -n and highlight the parts that have changed from previous results with -d.

It is useful when observing continuously changing values, such as memory, disk, process, or network status, over a short period of time. To exit, you typically use q or Ctrl+c.

What is the watch command?

watch is a program included in the procps-ng toolset. It repeatedly executes the standard output and standard error of the command and displays the first screen's worth, allowing you to check the result changes without entering the same command multiple times.

At the top of the default screen, information such as the execution interval, the executed command, host, time, and termination status is displayed. If the execution results are longer than the screen, parts may be hidden, so other tools may be more suitable for tracking long logs or large amounts of output.

You can check the default behavior and current options in the watch(1) manual and the procps-ng watch manual source.

Basic Syntax and Usage

watch [option] command [command arguments...]

If you repeatedly run free -h without any options, the memory usage is updated every 2 seconds by default.

watch free -h

To run at 1-second intervals, add the -n option.

watch -n 1 free -h

The watch option should be placed before the command to be repeated. Options written after the command are usually passed to the repeated command, not to watch.

Frequently used options

Option Function Usage
-n seconds Specify the execution interval Specify a time value in seconds like watch -n 1 command.
-d Highlight the changed parts Highlights the characters that have changed compared to the previous screen.
-d=permanent Cumulative change highlighting Continues to highlight any parts that have changed at least once since the first execution.
-g Exit when output changes Can be used to wait until a file or status changes.
-e Stop updating on command error If the repeated command ends with a non-zero status, it pauses the screen and exits after a key press.
-b Beep on command error If the repeated command returns a non-zero state, it will sound the terminal bell.
-p Attempt exact start intervals Execute according to the specified interval based on the start time of the previous run.
-t Hide top title Secure a little more space to display the command results.
-c Interpret ANSI colors Display the supported colors and styles output by the repeated command.
-w Prevent line wrapping of long lines Displays lines that exceed the screen width by cutting them off instead of wrapping them to the next line.
-x Run without going through the shell Instead of sh -c, run programs directly without using shell expansion and pipes.

The options supported may vary depending on the version of procps-ng included in the distribution. You can check the options available on your current system with the following command.

watch --help
watch --version

Controlling interval and output changes

Specify the execution interval with -n

Specify a value in seconds after -n or --interval. You can also use decimals, but too short an interval can place unnecessary load on the CPU, disk, network, and target services.

watch -n 0.5 date
watch -n 5 df -h

If the interval is omitted, the default is 2 seconds. In the current procps-ng manual, a limit is applied to excessively small or large values, and it is recommended to check the specific range in the installed version.

Highlight changes with -d

-d highlights parts that have changed by comparing the current screen with the previous one. It is convenient when viewing memory, process, and network statistics that change rapidly.

watch -n 1 -d free -h

To continuously display all changed locations after the first screen, use -d=permanent if the installed version supports it.

watch -n 1 -d=permanent free -h

Exit when changes occur with -g

-g or --chgexit exits watch when the visible output on the screen changes. It can be used when waiting for file modification times or deployment task statuses to change.

watch -g -n 1 'stat -c %Y /tmp/result.txt'

If the output only changes in areas cut off by the screen range, changes may not be detected. For automation where change detection is critical, it is safer to use the exit status of the target command or dedicated monitoring tools rather than comparing screen output.

Why quotes are needed when using pipes and shell syntax

By default, watch executes the passed command through sh -c. If you want to use pipes, redirection, semicolons, variables, and wildcards as part of the repeated command, it is clearer to wrap the entire command in single quotes.

Simple commands are passed as they are

Commands without pipes or redirection can be written directly like this.

watch -n 2 ls -lh /var/log

Pipes and variables wrap the entire command

In the following example, single quotes prevent the current shell from processing the pipe first and pass the entire command to the shell that will execute it repeatedly.

watch -n 1 'ps -eo pid,comm,%cpu,%mem --sort=-%cpu | head -n 15'

Redirection or multiple commands are wrapped in the same way.

watch -n 5 'date; df -h / /var'

The -x option runs the program directly without going through the shell. This can slightly reduce execution cost and simplify argument passing, but shell features like pipes, redirection, variable expansion, and wildcards cannot be used.

watch -x -n 2 ls -lh /var/log

The general behavior of quotes can be found in the GNU Bash Quoting documentation.

Examples frequently used in practice

Items to Check Description
Memory Updates the free -h result every second and highlights the changed parts.
Disk Space Checks the usage of the root and /var file systems every 5 seconds.
CPU-Using Processes Sorts the ps results by CPU usage and shows the top entries.
Socket Summary Check the overall status of network sockets repeatedly with ss -s.
File Size Observe changes in the size of downloaded or compressed files with stat.
Service Status Repeatedly run systemctl status with --no-pager.

Memory Usage

watch -n 1 -d free -h

Disk Usage

watch -n 5 'df -h / /var'

Processes with high CPU usage

watch -n 1 'ps -eo pid,comm,%cpu,%mem --sort=-%cpu | head -n 15'

Network socket summary

watch -n 1 ss -s

File size and modification time

watch -n 1 'stat -c "%s bytes  %y" archive.tar'

Service Status

watch -n 2 'systemctl --no-pager --full status nginx'

Commands that can produce long output, like service status, may only show partially depending on the terminal size. If the purpose is continuous log tracking, a command suited for that function, such as journalctl -f -u nginx, is more appropriate.

Exact execution intervals and long-running commands

In the default behavior, after a single command execution finishes, it waits for the specified interval before starting the next execution. Using -p or --precise tries to align the next start time based on when the previous command started.

watch -p -n 10 'date; curl -fsS https://example.com/health'

If the execution time of a repeated command is longer than the specified interval, watch will not run multiple instances simultaneously but will wait for the current command to finish. For batch tasks that require exact cycles and guaranteed execution, using a systemd timer or a task scheduler is more suitable than watch.

Controlling with the keyboard

Key Action
q Exits watch. The running child command may not stop immediately.
Ctrl+c Sends an interrupt signal to exit both watch and the running task.
Space Requests command execution without waiting for the next scheduled time. If already running, it starts the next execution immediately after completion without delay.

Key actions may vary depending on the procps-ng version, so first check the current system's man watch.

Precautions when using watch

  • Preferably use for read-only check commands: Repeating commands that change state, such as delete, payment, user creation, or service restart, can lead to undesired results.
  • Avoid very short intervals: Running database queries, remote API requests, or large directory searches at very short intervals can put a load on the system or external services.
  • Check the visible range on the screen: -g and -d are affected by the output displayed in the terminal, so changes in the truncated area may not be detected.
  • Avoid interactive commands: Programs that wait for user input, such as password prompts, editors, or pagers, are not suitable for repeated execution.
  • Distinguish exit status: The success status of the basic watch does not always mean that the repeated command succeeded. If you need to respond to command errors, check options like -e in the current version.

When other tools are more suitable than watch

Purpose Suitable tools
Tracking logs being appended to a file tail -f or tail -F
Tracking systemd service logs journalctl -f -u service_name
Checking process resource usage top or htop
Scheduled repetitive tasks systemd timer or cron
Long-term metrics collection and alerts Dedicated Monitoring System

watch is suitable for a person to observe short-term changes on the terminal. If you need record keeping, notifications, and long-term analysis, you should choose a tool appropriate for that purpose.

Frequently Asked Questions

It says the watch command does not exist

watch is usually included in the procps or procps-ng package. It may not be present in minimal installation environments, so you need to install the package using the package manager of your current distribution. Check the distribution documentation for the package name and installation command.

Aliases or shell functions do not execute inside watch

Aliases and functions may only be defined in the current interactive shell, and they may not be passed to the sh -c environment that watch calls by default. For repetitive tasks, it is easier to predictably use the actual executable, an explicit command, or a separate shell script.

Command colors are not displayed

Enable ANSI color interpretation with watch -c, and set the repeated command to output color codes in non-interactive environments as well. Depending on the program, a separate option like --color=always may be necessary.

Why should commands that include pipes be enclosed in quotes?

Without quotes, the current shell may process the pipe first, causing the entire output of watch to be passed to another command. Enclosing the entire pipeline in single quotes allows watch to pass it as a single command string to the shell that will repeatedly execute it.

Summary

watch is a simple observation tool that repeatedly displays the results of a command at the default 2-second interval. You can change the interval with -n, highlight changes with -d, and exit when the output changes with -g.

Commands that include pipes and redirection should be enclosed entirely in single quotes, and the load and side effects of repeated execution on the system should be checked. You can find the purposes of other commands by task in the Linux command list.

More in This Category
Linux ssh Command: Connect to a Remote Host Securely

Linux ssh Command: Connect to a Remote Host Securely

Learn how to connect to a Remote Host Securely with the Linux ssh command, including practical examples, key options, and important precautions.

Linux diff Command: Compare Text Files and Directories

Linux diff Command: Compare Text Files and Directories

Learn how Linux diff compares text files and directories, produces unified patches, ignores selected whitespace changes, and reports differences through exit status.

Linux id Command: Show User and Group IDs

Linux id Command: Show User and Group IDs

Learn how to show User and Group IDs with the Linux id command, including practical examples, key options, and important precautions.

Linux uniq Command: Remove or Count Adjacent Duplicate Lines

Linux uniq Command: Remove or Count Adjacent Duplicate Lines

Learn how to remove or count adjacent duplicate lines with the Linux uniq command, including practical examples, key options, and important precautions.

Linux top Command: Monitor Processes in Real Time

Linux top Command: Monitor Processes in Real Time

Learn how to monitor Processes in Real Time with the Linux top command, including practical examples, key options, and important precautions.

Linux df Command: Check Filesystem Free Space

Linux df Command: Check Filesystem Free Space

Learn how to check Filesystem Free Space with the Linux df command, including practical examples, key options, and important precautions.

Linux hostnamectl Command: Show and Change the Host Name

Linux hostnamectl Command: Show and Change the Host Name

Learn how to show and Change the Host Name with the Linux hostnamectl command, including practical examples, key options, and important precautions.

Linux dd Command: Copy and Convert Data by Blocks

Linux dd Command: Copy and Convert Data by Blocks

Learn how to copy and convert files or block devices with Linux dd, choose block sizes and ranges, display progress, verify results, and avoid overwriting the wrong device.

Linux uptime Command: Check Uptime and Load Averages

Linux uptime Command: Check Uptime and Load Averages

Learn how to use the Linux uptime command to check how long the system has been running and interpret load averages, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux tmux Command: Detach and Reattach Terminal Sessions

Linux tmux Command: Detach and Reattach Terminal Sessions

Learn how to detach and Reattach Terminal Sessions with the Linux tmux command, including practical examples, key options, and important precautions.