Guide · Linux servers

Linux server disk full:find what is using the space

A full disk usually has one or two obvious causes. Work from the top down, read before you delete, and never remove files under /var/lib by hand unless you know which service owns them.

← All guides

1. Confirm which filesystem is full

Run df -h. Look at the Use% column and the Mounted on column: the full filesystem might be / or a separate /var, /home or /data mount, and cleaning the wrong one changes nothing.

Also run df -i. A filesystem can have free space but no free inodes, which happens when millions of tiny files pile up (sessions, mail queues, cache files). If IUse% is near 100%, you are hunting for many small files, not a few big ones.

2. Find the biggest directories

Run sudo du -xh --max-depth=1 / | sort -h and read the last lines. The -x option stays on one filesystem, so mounted disks and virtual filesystems do not distort the result. Repeat inside the largest directory, for example sudo du -xh --max-depth=1 /var | sort -h.

If ncdu is installed (sudo apt install ncdu on Debian and Ubuntu), sudo ncdu -x / lets you move through the same data interactively.

3. Check for deleted files that are still open

If du shows far less than df, a process may still hold a deleted file open, often a large log. sudo lsof +L1 lists open files with a link count of zero. The space returns when that process closes the file, which usually means restarting the service that owns it. Do that in a quiet moment, not in the middle of a request peak.

4. Review the usual suspects

Logs: look in /var/log and check the journal with journalctl --disk-usage. See our guide on limiting the journald size if it is large.

Packages: sudo apt clean removes downloaded package files; sudo apt autoremove lists packages and old kernels that are no longer needed, and shows what it will remove before you confirm. Keep the running kernel and one previous version.

Docker: docker system df shows images, containers, volumes and build cache. docker system prune removes stopped containers, unused networks and dangling images; it does not remove volumes unless you add --volumes, so read the prompt before you answer.

Snap: snap list --all shows old revisions of snaps that are disabled and can be removed one at a time with snap remove NAME --revision=NUMBER.

5. After you free space

Run df -h again and check that services which stopped because of the full disk are running (systemctl --failed). A database that hit a full disk may need a restart or a check before you trust it.

Then put a limit in place so it does not repeat: log rotation, a journald limit, and an alert before the disk reaches 90%.

Want a clearer view of storage and maintenance across your Linux servers?RainServer combines a lightweight agent with a cloud dashboard for VPS monitoring and maintenance.Try RainServer free for 7 days →  ·  All guides →

Last updated: 2026-10-03

Quick questions

Read next

Download

Try it on your own machine.

Free, no account, no subscription. Windows 10 and 11.