ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Linux Server

Linux Disk Full? How to Check and Free Up Disk Space and Find Large Files

7 steps 11 min read 1599 views 52
On this page

Sites that will not load, databases that fail to write and the message "No space left on device" usually mean the disk is full. This guide shows practical ways to check and free up disk space on Linux: locate usage with df -h and du, analyse it interactively with ncdu, find large files with find, and safely clean system logs, package caches and Docker data. Commands apply to Debian/Ubuntu and CentOS/Rocky/AlmaLinux; run them as root.

Step 1: Check Disk Space Usage with df -h

df -hT shows the size, used space and usage percentage of each filesystem, so you can see which mount point is close to 100%. Also run df -i to check inodes: if millions of small files (caches, sessions) exhaust the inodes, you will get "disk full" errors even with free space left.

df -hT          # space usage per filesystem
df -i           # inode usage (100% also means "No space left on device")

Step 2: Locate Large Directories with du

Measure every top-level directory, sort by size and drill into the largest one. The -x flag keeps du on the current filesystem so mounted data disks are not counted. Typical space hogs are /var/log, /var/lib/docker, /var/lib/mysql, website folders and backup directories.

# Size of each top-level directory on the root filesystem, largest last
du -xh --max-depth=1 / 2>/dev/null | sort -h

# Drill down, e.g. into /var
du -xh --max-depth=1 /var 2>/dev/null | sort -h

Step 3: Analyse Disk Usage Interactively with ncdu

ncdu is a terminal disk analyser. After scanning you can browse directories with the arrow keys and press d to delete, which is much faster than running du repeatedly.

# Debian / Ubuntu
apt install -y ncdu

# CentOS / Rocky / AlmaLinux (ncdu is in EPEL)
dnf install -y epel-release && dnf install -y ncdu

ncdu -x /

Step 4: Find Large Files on Linux

List every file over 500 MB. This quickly reveals forgotten backup archives, database dumps or runaway logs. Confirm what a file is before deleting it; if unsure, move it to another disk first.

# Files larger than 500 MB on the root filesystem
find / -xdev -type f -size +500M -exec ls -lh {} \; 2>/dev/null | sort -k5 -h

Step 5: Clean System Logs and Package Caches

The systemd journal can grow to several gigabytes over time; trim it by size or age with journalctl. Do not rm a large log that a program is still writing to — empty it with truncate instead, otherwise the space is not released. Package caches are safe to clear.

journalctl --disk-usage
journalctl --vacuum-size=200M
journalctl --vacuum-time=7d

# Empty a large log file that a running program still writes to (do not rm it)
truncate -s 0 /var/log/nginx/access.log

# Package manager caches
apt clean                 # Debian / Ubuntu
dnf clean all             # CentOS / Rocky / AlmaLinux

To stop the journal from growing again, set a size cap:

# Permanently cap the journal size
mkdir -p /etc/systemd/journald.conf.d
printf '[Journal]\nSystemMaxUse=500M\n' > /etc/systemd/journald.conf.d/size.conf
systemctl restart systemd-journald

Step 6: Free Up Docker Disk Space

On Docker hosts, stopped containers, unused images and build cache keep piling up in /var/lib/docker. Check usage with docker system df and prune what you no longer need.

docker system df
docker container prune -f
docker image prune -a -f
docker builder prune -f
# Removes everything unused, including volumes - check first!
docker system prune -a --volumes
Pruning with --volumes deletes every volume not used by a container, which may include database data. Make sure you do not need them before running it.

Step 7: Release Space Held by Deleted Files

If you deleted a big file but df shows no change, a process still has it open. Find it with lsof and restart that service to release the space.

# Deleted files still held open by a process
lsof +L1 2>/dev/null | head -n 20
# Restart the process that holds them, e.g.
systemctl restart nginx

FAQ

Why do du and df report different usage?

Usually for one of two reasons: deleted files still held open by a process (see Step 7), or files hidden underneath a mount point by a disk mounted on top. Restart the process in the first case; unmount and inspect the directory in the second.

Which logs in /var/log are safe to delete?

Rotated logs with dates or a .gz suffix can generally be removed. Empty active logs with truncate. The long-term fix is to configure logrotate to rotate and compress logs regularly.

Still not enough space after cleaning?

Move websites, databases or backups to a data disk, or upgrade the disk and extend the partition following our LVM/growpart guide.

Still stuck after following these steps? Open a support ticket and the IMIDC 24/7 technical team will help. Please include the server IP, operating system, the commands you ran and a screenshot of the error so we can pinpoint the issue faster.

Was this answer helpful?

Related Tutorials