Start with two commands:
df -hT
sudo du -xhd1 / | sort -h
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsdf shows how full each mounted filesystem is. du identifies the directories consuming space on one filesystem. If their totals disagree, investigate mounts, deleted-but-open files, inodes, quotas, snapshots, and filesystem-specific accounting rather than deleting files at random.
Check free space with df
Run:
df -hT
With no path, df reports every mounted filesystem. Supplying a path reports the filesystem containing that path, for example df -hT /var. The output commonly looks like this:
Filesystem Type Size Used Avail Use% Mounted on
/dev/nvme0n1p2 ext4 200G 168G 22G 89% /
- Filesystem: the device or virtual filesystem.
- Type: such as
ext4,xfs,btrfs,tmpfs, orsquashfs. - Size: total filesystem capacity.
- Used: allocated space reported by the filesystem.
- Avail: space available to the invoking user; reservations and quotas can make it lower than raw free blocks.
- Use%: percentage used.
- Mounted on: the path where the filesystem is attached.
Useful variations include:
df -h /
df -h /home
df -hT /var
df -H
df -BM
GNU df -h uses binary-style powers of 1024 for human-readable values, while -H uses powers of 1000. -B M requests a specified block size. Do not compare figures displayed with different unit conventions. See the df manual and GNU df options.
Check inode capacity too
Bytes can remain available while every inode is consumed by millions of small files:
#1 Best Overall
- Easily store and access 2TB to content on the go with the Seagate Portable Drive, a USB external hard drive
- Designed to work with Windows or Mac computers, this external hard drive makes backup a snap just drag and drop
- To get set up, connect the portable hard drive to a computer for automatic recognition no software required
- This USB drive provides plug and play simplicity with the included 18 inch USB 3.0 cable
- The available storage capacity may vary.
df -ih
Check Inodes, IUsed, IFree, and IUse%. Mail queues, session files, caches, temporary files, package metadata, and container layers are common causes. Count files in likely locations:
sudo find /var -xdev -type f 2>/dev/null | wc -l
sudo find /tmp -xdev -type f 2>/dev/null | wc -l
Byte capacity and inode capacity are separate limits; df -h cannot substitute for df -i.
Find the largest directories with du
After identifying a crowded mount point, summarize one level without crossing into other filesystems:
sudo du -xhd1 / | sort -h
For a specific branch:
sudo du -xhd1 /var | sort -h
sudo du -xhd1 /home | sort -h
sudo du -xhd1 /var/lib | sort -h
sudoallows traversal of directories your account cannot read.-xstays on the filesystem containing the starting path.-hprints human-readable sizes.-d1summarizes one directory level.sort -horders human-readable values numerically.
Descend into the largest result and repeat. A plain du -sh /* can include mounted /home, network shares, container mounts, or removable media, so it is a poor baseline for auditing the root filesystem. GNU du behavior is documented in the du manual.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Without sufficient permissions, the report may be incomplete. For troubleshooting, preserve errors instead of silently assuming every directory was examined:
sudo du -xhd1 / > /tmp/du.out 2> /tmp/du.errors
Locate unusually large individual files
GNU find can list files over 1 GiB and show the 20 largest by byte count:
Rank #2
- Get NVMe solid state performance with up to 1050MB/s read and 1000MB/s write speeds in a portable, high-capacity drive(1) (Based on internal testing; performance may be lower depending on host device & other factors. 1MB=1,000,000 bytes.)
- Up to 3-meter drop protection and IP65 water and dust resistance mean this tough drive can take a beating(3) (Previously rated for 2-meter drop protection and IP55 rating. Now qualified for the higher, stated specs.)
- Use the handy carabiner loop to secure it to your belt loop or backpack for extra peace of mind.
- Help keep private content private with the included password protection featuring 256‐bit AES hardware encryption.(3)
- Easily manage files and automatically free up space with the SanDisk Memory Zone app.(5). Non-Operating Temperature -20°C to 85°C
sudo find / -xdev -type f -size +1G
-printf '%s %pn' 2>/dev/null |
sort -n |
tail -20
For readable sizes:
sudo find / -xdev -type f -size +1G
-printf '%st%pn' 2>/dev/null |
sort -n |
tail -20 |
numfmt --field=1 --to=iec
-printf and numfmt are GNU extensions, so they may not exist on other Unix-like systems. A large file might be sparse, compressed, reflinked, a database, a virtual-disk image, or active application data. Establish its owner and purpose before removing it. Portable predicate details are in the POSIX find specification.
Compare apparent and allocated size
ls -lh file.img
du -h file.img
du --apparent-size -h file.img
A sparse file can have a large apparent length while occupying relatively few blocks. GNU du distinguishes apparent size from filesystem allocation; holes, internal fragmentation, indirect blocks, compression, and shared extents affect the comparison.
Why df and du disagree
df reads filesystem accounting for allocated and available blocks. du walks directory entries visible from a path. They measure different layers, so exact equality is not expected.
| Symptom | Likely cause | Check |
|---|---|---|
df is high while du is much lower |
Deleted file still open by a process | sudo lsof +L1 |
| Root total includes unexpected data | Other filesystems are mounted below the path | findmnt; repeat du with -x |
| Btrfs totals are confusing | Snapshots, compression, reflinks, or shared extents | btrfs filesystem usage |
| Free bytes exist but file creation fails | Inodes are exhausted | df -ih |
| A user receives a quota error | User, group, project, or inode quota | quota or xfs_quota |
Deleted-but-open files
Removing a pathname does not release its blocks while a process still has the file open. The pathname disappears from du, but the allocation remains in df:
sudo lsof +L1
Look for large entries marked (deleted). Restart or otherwise close the owning service through its normal service manager. Do not terminate a critical process without understanding its role. The lsof documentation describes +L1 for unlinked open files.
Data hidden beneath a mount point
Files created in a directory before another filesystem is mounted there become invisible during normal traversal, although they still occupy the underlying filesystem. Map mounts with:
Rank #3
- High capacity in a small enclosure – The small, lightweight design offers up to 6TB* capacity, making WD Elements portable hard drives the ideal companion for consumers on the go.
- Plug-and-play expandability
- Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
- SuperSpeed USB 3.2 Gen 1 (5Gbps)
findmnt
findmnt -T /var
findmnt -R /
findmnt -T PATH identifies the filesystem serving a path. Its default display is intended for humans; scripts should request explicit columns as described in the findmnt manual.
Metadata, reservations, snapshots, and compression
Filesystem metadata and reserved blocks count in filesystem accounting but are not ordinary files. Snapshots can retain old data after visible files are deleted. Reflinks and compression can make logical directory totals differ from physical allocation. These effects are particularly significant on Btrfs.
Inspect disks, partitions, and mount points
df starts at mounted filesystems. To see the device topology underneath them:
lsblk -o NAME,SIZE,FSTYPE,FSAVAIL,FSUSE%,MOUNTPOINTS
lsblk -f
lsblk -e7
lsblk can show physical disks, partitions, encrypted mappings, RAID, logical volumes, loop devices, and unmounted filesystems. Metadata depends on the installed version, udev, and permissions; consult the lsblk manual.
findmnt -o TARGET,SOURCE,FSTYPE,FSAVAIL,FSUSE%,OPTIONS
findmnt -T /home
A disk can contain unmounted partitions that never appear in ordinary df output. Conversely, one mounted path can sit above several device-mapping layers.
Exclude pseudo-filesystems when appropriate
Systems commonly expose tmpfs, devtmpfs, proc, sysfs, and squashfs. To focus a human review on likely persistent storage:
Rank #4
- Safe Data Storage: ADATA HD710 Pro External Hard Drive is a ruggedized hard drive built to keep your data secure for years to come in a travel-friendly design built for every adventure
- Military-Grade Toughness: Features durable, triple-layered construction with a USB 3.1 interface, an IP68 waterproof and IP6X dustproof design, and IP68 military-grade shock resistance (MIL-STD-810G 516.6)
- Built for Anyone: Ultra-fast data transfer capability makes this a great hard drive for gamers, students, and professionals; enough storage capacity for creatives and DIY PC users
- Easy Data Storage: Compatible with Linus, Mac, and PC, this external hard drive also features neat cable management for easy storage and a clean data solution
- About ADATA: ADATA means number 1 in data storage; we offer premium storage capacity, high speeds, and optimized durability, all while innovating and investing in a sustainable future
df -hT -x tmpfs -x devtmpfs -x squashfs
The exact filesystem types differ by distribution, boot configuration, containers, and desktop environment, so do not hard-code this filter in a portable script. For directory traversal, du -x is the safer boundary.
Check logs, Docker, and other common consumers
systemd journal
journalctl --disk-usage
To remove archived journal files until their archived total is below a target:
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →sudo journalctl --vacuum-size=500M
sudo journalctl --vacuum-time=14d
--vacuum-size acts on archived files. Active journal files can still contribute to the amount reported by --disk-usage, so the final total need not equal the requested threshold. Do not delete files directly from /var/log/journal while journald is active. See the journalctl documentation.
Docker storage
docker system df
docker system df -v
Docker reports images, containers, local volumes, and build cache. Verbose mode can be resource-intensive because it traverses image, container, and volume filesystems. Docker data is often under /var/lib/docker, but the daemon root can be configured elsewhere and rootless Docker uses a different location.
Potential cleanup commands include:
docker image prune
docker container prune
docker volume prune
docker builder prune
docker system prune
These are cleanup operations, not diagnostics. Pruning can remove objects not attached to running containers; volumes can contain databases or user data. Confirm what is reclaimable and who owns it before proceeding. Details are in Docker’s system df reference.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Filesystem-specific investigations
Btrfs
df -hT
sudo btrfs filesystem usage /
sudo btrfs filesystem du -s /
Btrfs reports data and metadata allocation and can account for shared extents. Snapshots, subvolumes, compression, reflinks, thin allocation, RAID profiles, and metadata exhaustion can all make ordinary du incomplete as an explanation of allocated space. Use the snapshot manager appropriate to your system—such as Snapper, Timeshift, or a vendor tool—rather than assuming a universal deletion command. The btrfs-filesystem manual explains these views.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
- 【Upgraded version】 - The mirror logo strip is combined with the striped non-slip design. The rounded corners of the shell are more suitable for holding. The strips play a heat dissipation function to ensure a stable and fast transmission process.
- 【Ultra-thin and quiet】 - The motherboard adopts JMicron 578 noise-free solution, giving you a quiet working environment. Lightweight and portable size designed to fit in your pocket for easy portability.
- 【Ultra-Fast Data Transfers】 - Pairing this external hard drive with JMicron 578 solution USB 3.0 and USB 2.0 interfaces enables blazing-fast data transfer. It boasts theoretical read speeds of up to 125MB/s and write speeds of up to 103MB/s.
- 【Plug and Play】 - With no software to install, just plug it in and the drive is ready to use.The hard disk chip is wrapped with an aluminum anti-interference layer to increase heat dissipation and protect data.
- 【What You Get】 - 1 x Portable Hard Drive, 1 x USB 3.0 Cable, 1 x User Manual, Gift-type shell packaging ,Three-year manufacturer's warranty and free technical support services.
Quotas
A filesystem can have free blocks while a user, group, project, directory tree, or inode limit is exhausted:
quota -s
quota -v
sudo repquota -a
For XFS:
sudo xfs_quota -x -c 'report -h' /
Use the quota tool only where quotas are configured. References: quota(1) and xfs_quota(8).
Containers, virtual machines, and network filesystems
Container layers, VM disk images, NFS, FUSE, and pseudo-filesystems can be slow or have accounting semantics unlike ordinary local files. Inspect them on their owning host or through the owning tool. Keep a root-filesystem audit confined with -x.
Use an interactive analyzer when navigation is the bottleneck
ncdu presents a terminal browser over a directory traversal:
Recommended Free Tools
ncdu -x /
Install it using your distribution’s package manager, for example:
sudo apt install ncdu
sudo dnf install ncdu
sudo pacman -S ncdu
Package names and repositories vary. ncdu is a navigation convenience, not a replacement for df, lsof, quota tools, or Btrfs accounting. GNOME desktops offer the graphical Baobab analyzer at apps.gnome.org/Baobab; it is useful for visible directory trees but not headless-server or deleted-open-file diagnosis.
A defensible investigation sequence
- Run
df -hTand note the crowded mount point and filesystem type. - Run
df -ihto separate byte exhaustion from inode exhaustion. - Use
findmnt -T /pathto confirm which filesystem serves the path. - Run
sudo du -xhd1 /mountpoint | sort -hand descend into the largest directory. - Search that filesystem for large files with GNU
find. - Check
journalctl --disk-usage,docker system df -v, andsudo lsof +L1when relevant. - Branch to Btrfs accounting or quota tools when the filesystem and symptoms require it.
Clean up safely
- Identify the owner and purpose of every candidate.
- Check whether a process still has it open.
- Confirm backups, retention requirements, and recoverability.
- Use the owning application’s cleanup or rotation mechanism.
- Re-run
dfand the relevant specialized command after cleanup.
On a completely full root filesystem, write diagnostic output to another writable filesystem, check deleted-open files before deleting more data, and avoid removing database files, VM images, container volumes, or system directories based only on size.
Quick Recap
Command cheat sheet
| Question | Command |
|---|---|
| How full are mounted filesystems? | df -hT |
| Are inodes exhausted? | df -ih |
| Which top-level directories are largest? | sudo du -xhd1 / | sort -h |
| Which files exceed 1 GiB? | sudo find / -xdev -type f -size +1G ... |
| Which filesystem serves a path? | findmnt -T /path |
| What devices and partitions exist? | lsblk -o NAME,SIZE,FSTYPE,FSAVAIL,FSUSE%,MOUNTPOINTS |
| Are deleted files holding blocks? | sudo lsof +L1 |
| How large is the systemd journal? | journalctl --disk-usage |
| How much Docker storage is managed? | docker system df -v |
| How is Btrfs allocation distributed? | sudo btrfs filesystem usage /mountpoint |
| Are quotas limiting a user? | quota -s or sudo xfs_quota -x -c 'report -h' /mountpoint |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Free tools Windows power users keep installed
One-click scans. No signup required.

