# Linux server disk full: find what is using the space

A full disk usually has one or two obvious causes. Work from the top down, read before you delete, and never remove files under /var/lib by hand unless you know which service owns them.

## 1. Confirm which filesystem is full

Run df -h. Look at the Use% column and the Mounted on column: the full filesystem might be / or a separate /var, /home or /data mount, and cleaning the wrong one changes nothing.
Also run df -i. A filesystem can have free space but no free inodes, which happens when millions of tiny files pile up (sessions, mail queues, cache files). If IUse% is near 100%, you are hunting for many small files, not a few big ones.

## 2. Find the biggest directories

Run sudo du -xh --max-depth=1 / | sort -h and read the last lines. The -x option stays on one filesystem, so mounted disks and virtual filesystems do not distort the result. Repeat inside the largest directory, for example sudo du -xh --max-depth=1 /var | sort -h.
If ncdu is installed (sudo apt install ncdu on Debian and Ubuntu), sudo ncdu -x / lets you move through the same data interactively.

## 3. Check for deleted files that are still open

If du shows far less than df, a process may still hold a deleted file open, often a large log. sudo lsof +L1 lists open files with a link count of zero. The space returns when that process closes the file, which usually means restarting the service that owns it. Do that in a quiet moment, not in the middle of a request peak.

## 4. Review the usual suspects

Logs: look in /var/log and check the journal with journalctl --disk-usage. See our guide on limiting the journald size if it is large.
Packages: sudo apt clean removes downloaded package files; sudo apt autoremove lists packages and old kernels that are no longer needed, and shows what it will remove before you confirm. Keep the running kernel and one previous version.
Docker: docker system df shows images, containers, volumes and build cache. docker system prune removes stopped containers, unused networks and dangling images; it does not remove volumes unless you add --volumes, so read the prompt before you answer.
Snap: snap list --all shows old revisions of snaps that are disabled and can be removed one at a time with snap remove NAME --revision=NUMBER.

## 5. After you free space

Run df -h again and check that services which stopped because of the full disk are running (systemctl --failed). A database that hit a full disk may need a restart or a check before you trust it.
Then put a limit in place so it does not repeat: log rotation, a journald limit, and an alert before the disk reaches 90%.

## FAQ

**Is it safe to delete files in /var/log?**

Rotated and compressed logs (for example syslog.1 or .gz files) can usually go once you no longer need them. Do not delete the current log file of a running service; truncate it carefully or let logrotate handle it, and check what the service expects first.

**Why does df show a full disk but du does not add up?**

Usually a deleted file is still held open by a running process (see lsof +L1), or the numbers come from different filesystems. Use du -x and compare against df for the same mount point.

**Should I run docker system prune on a production server?**

Only after docker system df and a look at what is unused. It can remove images you still intend to start. Volumes are kept by default, but make sure you have backups of anything important.

Source: https://raincleaner.eu/guides/linux-server-disk-full-find-what-is-using-space