Linux watch Command: Run a Command Repeatedly
watch is a command that repeatedly executes a specified command at regular intervals and updates the entire terminal screen with the results. The default execution interval is 2 seconds, and you can change the interval with -n and highlight the parts that have changed from previous results with -d.
It is useful when observing continuously changing values, such as memory, disk, process, or network status, over a short period of time. To exit, you typically use q or Ctrl+c.
What is the watch command?
watch is a program included in the procps-ng toolset. It repeatedly executes the standard output and standard error of the command and displays the first screen's worth, allowing you to check the result changes without entering the same command multiple times.
At the top of the default screen, information such as the execution interval, the executed command, host, time, and termination status is displayed. If the execution results are longer than the screen, parts may be hidden, so other tools may be more suitable for tracking long logs or large amounts of output.
You can check the default behavior and current options in the watch(1) manual and the procps-ng watch manual source.
Basic Syntax and Usage
watch [option] command [command arguments...]
If you repeatedly run free -h without any options, the memory usage is updated every 2 seconds by default.
watch free -h
To run at 1-second intervals, add the -n option.
watch -n 1 free -h
The watch option should be placed before the command to be repeated. Options written after the command are usually passed to the repeated command, not to watch.
Frequently used options
| Option | Function | Usage |
|---|---|---|
-n seconds |
Specify the execution interval | Specify a time value in seconds like watch -n 1 command. |
-d |
Highlight the changed parts | Highlights the characters that have changed compared to the previous screen. |
-d=permanent |
Cumulative change highlighting | Continues to highlight any parts that have changed at least once since the first execution. |
-g |
Exit when output changes | Can be used to wait until a file or status changes. |
-e |
Stop updating on command error | If the repeated command ends with a non-zero status, it pauses the screen and exits after a key press. |
-b |
Beep on command error | If the repeated command returns a non-zero state, it will sound the terminal bell. |
-p |
Attempt exact start intervals | Execute according to the specified interval based on the start time of the previous run. |
-t |
Hide top title | Secure a little more space to display the command results. |
-c |
Interpret ANSI colors | Display the supported colors and styles output by the repeated command. |
-w |
Prevent line wrapping of long lines | Displays lines that exceed the screen width by cutting them off instead of wrapping them to the next line. |
-x |
Run without going through the shell | Instead of sh -c, run programs directly without using shell expansion and pipes. |
The options supported may vary depending on the version of procps-ng included in the distribution. You can check the options available on your current system with the following command.
watch --help watch --version
Controlling interval and output changes
Specify the execution interval with -n
Specify a value in seconds after -n or --interval. You can also use decimals, but too short an interval can place unnecessary load on the CPU, disk, network, and target services.
watch -n 0.5 date watch -n 5 df -h
If the interval is omitted, the default is 2 seconds. In the current procps-ng manual, a limit is applied to excessively small or large values, and it is recommended to check the specific range in the installed version.
Highlight changes with -d
-d highlights parts that have changed by comparing the current screen with the previous one. It is convenient when viewing memory, process, and network statistics that change rapidly.
watch -n 1 -d free -h
To continuously display all changed locations after the first screen, use -d=permanent if the installed version supports it.
watch -n 1 -d=permanent free -h
Exit when changes occur with -g
-g or --chgexit exits watch when the visible output on the screen changes. It can be used when waiting for file modification times or deployment task statuses to change.
watch -g -n 1 'stat -c %Y /tmp/result.txt'
If the output only changes in areas cut off by the screen range, changes may not be detected. For automation where change detection is critical, it is safer to use the exit status of the target command or dedicated monitoring tools rather than comparing screen output.
Why quotes are needed when using pipes and shell syntax
By default, watch executes the passed command through sh -c. If you want to use pipes, redirection, semicolons, variables, and wildcards as part of the repeated command, it is clearer to wrap the entire command in single quotes.
Simple commands are passed as they are
Commands without pipes or redirection can be written directly like this.
watch -n 2 ls -lh /var/log
Pipes and variables wrap the entire command
In the following example, single quotes prevent the current shell from processing the pipe first and pass the entire command to the shell that will execute it repeatedly.
watch -n 1 'ps -eo pid,comm,%cpu,%mem --sort=-%cpu | head -n 15'
Redirection or multiple commands are wrapped in the same way.
watch -n 5 'date; df -h / /var'
The -x option runs the program directly without going through the shell. This can slightly reduce execution cost and simplify argument passing, but shell features like pipes, redirection, variable expansion, and wildcards cannot be used.
watch -x -n 2 ls -lh /var/log
The general behavior of quotes can be found in the GNU Bash Quoting documentation.
Examples frequently used in practice
| Items to Check | Description |
|---|---|
| Memory | Updates the free -h result every second and highlights the changed parts. |
| Disk Space | Checks the usage of the root and /var file systems every 5 seconds. |
| CPU-Using Processes | Sorts the ps results by CPU usage and shows the top entries. |
| Socket Summary | Check the overall status of network sockets repeatedly with ss -s. |
| File Size | Observe changes in the size of downloaded or compressed files with stat. |
| Service Status | Repeatedly run systemctl status with --no-pager. |
Memory Usage
watch -n 1 -d free -h
Disk Usage
watch -n 5 'df -h / /var'
Processes with high CPU usage
watch -n 1 'ps -eo pid,comm,%cpu,%mem --sort=-%cpu | head -n 15'
Network socket summary
watch -n 1 ss -s
File size and modification time
watch -n 1 'stat -c "%s bytes %y" archive.tar'
Service Status
watch -n 2 'systemctl --no-pager --full status nginx'
Commands that can produce long output, like service status, may only show partially depending on the terminal size. If the purpose is continuous log tracking, a command suited for that function, such as journalctl -f -u nginx, is more appropriate.
Exact execution intervals and long-running commands
In the default behavior, after a single command execution finishes, it waits for the specified interval before starting the next execution. Using -p or --precise tries to align the next start time based on when the previous command started.
watch -p -n 10 'date; curl -fsS https://example.com/health'
If the execution time of a repeated command is longer than the specified interval, watch will not run multiple instances simultaneously but will wait for the current command to finish. For batch tasks that require exact cycles and guaranteed execution, using a systemd timer or a task scheduler is more suitable than watch.
Controlling with the keyboard
| Key | Action |
|---|---|
q |
Exits watch. The running child command may not stop immediately. |
Ctrl+c |
Sends an interrupt signal to exit both watch and the running task. |
Space |
Requests command execution without waiting for the next scheduled time. If already running, it starts the next execution immediately after completion without delay. |
Key actions may vary depending on the procps-ng version, so first check the current system's man watch.
Precautions when using watch
- Preferably use for read-only check commands: Repeating commands that change state, such as delete, payment, user creation, or service restart, can lead to undesired results.
- Avoid very short intervals: Running database queries, remote API requests, or large directory searches at very short intervals can put a load on the system or external services.
- Check the visible range on the screen:
-gand-dare affected by the output displayed in the terminal, so changes in the truncated area may not be detected. - Avoid interactive commands: Programs that wait for user input, such as password prompts, editors, or pagers, are not suitable for repeated execution.
- Distinguish exit status: The success status of the basic
watchdoes not always mean that the repeated command succeeded. If you need to respond to command errors, check options like-ein the current version.
When other tools are more suitable than watch
| Purpose | Suitable tools |
|---|---|
| Tracking logs being appended to a file | tail -f or tail -F |
| Tracking systemd service logs | journalctl -f -u service_name |
| Checking process resource usage | top or htop |
| Scheduled repetitive tasks | systemd timer or cron |
| Long-term metrics collection and alerts | Dedicated Monitoring System |
watch is suitable for a person to observe short-term changes on the terminal. If you need record keeping, notifications, and long-term analysis, you should choose a tool appropriate for that purpose.
Frequently Asked Questions
It says the watch command does not exist
watch is usually included in the procps or procps-ng package. It may not be present in minimal installation environments, so you need to install the package using the package manager of your current distribution. Check the distribution documentation for the package name and installation command.
Aliases or shell functions do not execute inside watch
Aliases and functions may only be defined in the current interactive shell, and they may not be passed to the sh -c environment that watch calls by default. For repetitive tasks, it is easier to predictably use the actual executable, an explicit command, or a separate shell script.
Command colors are not displayed
Enable ANSI color interpretation with watch -c, and set the repeated command to output color codes in non-interactive environments as well. Depending on the program, a separate option like --color=always may be necessary.
Why should commands that include pipes be enclosed in quotes?
Without quotes, the current shell may process the pipe first, causing the entire output of watch to be passed to another command. Enclosing the entire pipeline in single quotes allows watch to pass it as a single command string to the shell that will repeatedly execute it.
Summary
watch is a simple observation tool that repeatedly displays the results of a command at the default 2-second interval. You can change the interval with -n, highlight changes with -d, and exit when the output changes with -g.
Commands that include pipes and redirection should be enclosed entirely in single quotes, and the load and side effects of repeated execution on the system should be checked. You can find the purposes of other commands by task in the Linux command list.









