Tired of repeatedly typing the same command into your Linux terminal to monitor system changes? Whether you’re tracking disk space during a massive file transfer or waiting for a critical service to initialize, manually re-executing commands is inefficient and prone to missed updates. Enter the powerful watch command – a simple yet indispensable Linux command-line utility that automates this repetitive task. This guide will reveal how watch can transform your Linux system monitoring by providing a live, constantly updated view of your system’s real-time system status, complete with highlighting changes and customizable intervals.
Simplify Linux System Monitoring with `watch`
The watch command is a dedicated utility for repeatedly running another command at a fixed interval and refreshing your terminal with its latest output. By default, it executes the specified command every 2 seconds, making it an invaluable tool for interactive system monitoring without the need for complex scripts.
This powerful utility is typically included in the procps package on Debian-based distributions and procps-ng on RHEL-based distributions. It’s usually installed by default on most modern Linux systems. However, if which watch doesn’t return a path, you can easily install it using your distribution’s package manager:
On Ubuntu/Debian:
sudo apt install procps
On RHEL/Rocky Linux:
sudo dnf install procps-ng
Note: sudo is required to run the installation with administrative privileges, which package managers need to install software system-wide.
This guide was tested on Ubuntu 26.04 and Rocky Linux 10, but the watch command operates consistently across most contemporary Linux distributions.
Getting Started with `watch`: Basic Syntax
The basic syntax for the watch command is straightforward:
watch [options] command
By default, watch reruns the specified command every 2 seconds and refreshes the screen with the latest output. For instance, to continuously monitor your disk space:
watch df -h
In this example:
watchinitiates the monitoring process.df -his the command that is repeatedly executed. The-hoption displays disk sizes in a human-readable format, such as MB or GB.
You can press Ctrl+C at any time to stop watch. It’s important to note that watch refreshes the screen by replacing the previous output, meaning it doesn’t maintain a history of past results unless you explicitly redirect its output to a file or use a logging tool.
Every 2.0s: df -h tecmint: Wed Aug 5 10:46:34 2026
Filesystem Size Used Avail Use% Mounted on
tmpfs 3.2G 2.0M 3.2G 1% /run
efivarfs 374K 222K 148K 61% /sys/firmware/efi/efivars
/dev/nvme0n1p1 458G 57G 378G 14% /
tmpfs 16G 336M 16G 3% /dev/shm
tmpfs 5.0M 8.0K 5.0M 1% /run/lock
tmpfs 16G 0 16G 0% /run/qemu
/dev/sda1 511M 6.2M 505M 2% /boot/efi
tmpfs 3.2G 136K 3.2G 1% /run/user/1000
Practical Applications of the `watch` Command
Real-time Disk Usage Monitoring (Example 1)
Imagine you’re copying a large file to a mounted NFS share. You need to keep an eye on available disk space for both the source and destination filesystems to prevent potential errors. Instead of repeatedly typing df -h, use watch:
watch -n 1 df -h /tmp /mnt/nfs-share
Here:
-n 1instructswatchto refresh the output every second, rather than the default 2 seconds.df -h /tmp /mnt/nfs-sharelimits the disk usage display to only the relevant source and destination filesystems.
As the copy progresses, you’ll observe the ‘Used’ space increasing and ‘Avail’ space decreasing on the destination filesystem. This real-time visibility helps confirm the operation is progressing as expected and allows you to proactively address low disk space issues before they cause failures. This is particularly useful when dealing with dynamic storage like cloud-mounted volumes or network shares.
Spotting Changes with Output Highlighting (Example 2)
When troubleshooting a service that unexpectedly opens or closes network ports, manually comparing ss command outputs can be tedious. The -d option for watch makes this incredibly easy:
watch -d ss -tunlp
Let’s break down the options:
-d(or--differences) highlights any discrepancies between the current and previous screen updates, making changes immediately noticeable.ss -tunlpdisplays active TCP and UDP sockets along with their associated process names.
As services start, stop, or establish new connections, watch will highlight the affected lines, allowing you to instantly identify what changed without the painstaking process of manual comparison.
Customizing Refresh Intervals for Dynamic Monitoring (Example 3)
For systems under heavy load or events with rapid changes, the default 2-second refresh interval might not be frequent enough. Monitoring CPU temperature spikes, for instance, often requires more granular updates:
watch -n 0.5 sensors
In this case:
-n 0.5sets the display refresh rate to every 0.5 seconds.sensorsoutputs hardware sensor information, including CPU and system temperatures.
The -n option accepts fractional seconds, enabling more frequent monitoring. However, remember that the actual refresh rate is ultimately constrained by how long the command itself takes to execute. If sensors requires 400 milliseconds to complete, setting the interval to 0.1 seconds won’t make the output update any faster.
Automated Exit on Output Change (Example 4)
After restarting a service, you might want to wait for it to be fully operational before proceeding with subsequent tasks. watch can automatically exit as soon as the command’s output changes, signaling readiness:
watch -g -n 2 'systemctl is-active nginx'
Here’s what each option does:
-g(or--chgexit) instructswatchto exit as soon as the command’s output differs from its initial run.-n 2checks the command every 2 seconds.systemctl is-active nginxreports the current state of the Nginx service (e.g., active, inactive, failed).
As soon as the service changes from its initial state – for example, from ‘activating’ to ‘active’ – watch will automatically exit. This is exceptionally useful for scripting sequences where one action depends on a service becoming ready.
For example, to execute a command immediately after Nginx becomes active:
watch -g 'systemctl is-active nginx' && echo "Nginx is ready!"
Once the service becomes active, watch exits, and the subsequent command (echo "Nginx is ready!") runs automatically.
Live Log File Snapshot Monitoring (Example 5)
When tweaking web server configurations, keeping an eye on error logs while sending test requests is crucial. While tail -f streams continuously, watch can provide a refreshing snapshot:
watch -n 1 -d 'tail -n 20 /var/log/nginx/error.log'
This command breaks down as follows:
-n 1refreshes the output every second.tail -n 20displays the last 20 lines of the log file on each refresh.-dhighlights any new or changed lines since the previous update, making new log entries easy to spot.
This approach isn’t a replacement for tail -f, which provides a continuous stream of new log entries. Instead, watch offers a refreshed snapshot of the latest log output, ideal for quickly checking whether new errors appear during configuration testing. A unique tip here is to also use `watch` to monitor specific filtered output, like `watch -n 2 ‘journalctl -u myapp –since “10 minutes ago” | grep ERROR’`, for a more targeted view of your application’s health.
Avoiding Common `watch` Command Pitfalls
While intuitive, there are a few common mistakes users make with the watch command:
- Forgetting to quote pipelines: Running
watch df -h | grep sdapipeswatch’s own screen output togrep, which is rarely the desired outcome. Instead, enclose the entire command in quotes sowatchexecutes it as a single unit:watch 'df -h | grep sda' - Using a refresh interval that’s too short: If the command itself takes longer to run than the specified refresh interval,
watchcannot update any faster. For instance, if a command requires 3 seconds to complete, setting-n 1will not produce updates every second. - Expecting scrollback or command history:
watchrefreshes the screen on every update, replacing the previous output. It does not maintain a history. If you need to preserve every line of output, redirect the command to a file or use a tool liketail -ffor log monitoring. - Using
watchwith interactive programs: Commands such astop,htop,vim, andnanomanage their own full-screen interfaces and are not designed to run insidewatch. Always run these programs directly.
`watch` vs. Bash Loops and Cron Jobs: When to Choose Which
The watch command isn’t the only way to repeatedly execute a command, but it’s often the simplest choice for interactive monitoring.
A Bash loop, such as:
while true; do
command
sleep 2
done
can repeatedly run a command, but it requires writing a script or typing a multi-line loop. For quick, interactive Linux system monitoring, watch achieves the same goal with a single command.
A cron job serves a distinctly different purpose. It’s designed to run commands automatically at scheduled times, typically every few minutes or hours, even when you’re not logged in. It’s not intended for continuously refreshing output on your terminal to display real-time system status.
Use watch when you need to interactively monitor a command and stop it as soon as you’re done. If you require saving the output, sending alerts, or running commands automatically in the background, a Bash script or cron job is a more appropriate choice. These powerful Linux command-line utilities each have their specific strengths.
Conclusion
The watch command is an indispensable Linux command-line utility that simplifies Linux system monitoring by automatically rerunning any specified command at regular intervals. Whether you’re checking disk usage, observing a service startup, or keeping an eye on log files, watch provides a live, dynamic view without the overhead of scripting.
You’ve learned how to customize refresh intervals with -n, highlight crucial changes with -d, and even automate exits when output changes using -g. The next time you find yourself repeatedly executing the same command, remember watch. It’s a straightforward tool that significantly streamlines system monitoring and enhances your command-line efficiency.
How do you integrate the watch command into your daily workflow? Share your favorite use cases or helpful tips with other Linux users in the comments!
FAQ
Question 1: Is the watch command installed by default on most Linux distributions?
Answer 1: Yes, the watch command is generally installed by default on most modern Linux distributions as part of the procps (Debian-based) or procps-ng (RHEL-based) packages. You can verify its presence by typing which watch in your terminal; if it returns a path, it’s installed.
Question 2: Can watch save its output to a file?
Answer 2: By itself, watch does not save its output to a file as it refreshes the screen by replacing previous content. However, you can redirect the output of the command being watched to a file. For example, watch 'df -h > disk_usage.log' would repeatedly overwrite disk_usage.log with the latest df -h output. If you need a continuous log of changes, consider running the command directly and redirecting its output (e.g., df -h >> logfile.txt in a loop) or using tools like tail -f for logs.
Question 3: What’s the key difference between using watch for log files and tail -f?
Answer 3: The main difference lies in their approach to displaying content. tail -f continuously streams new lines as they are appended to a file, preserving all historical output as it arrives. In contrast, watch repeatedly re-executes a command (like tail -n X file) and refreshes the entire screen with the command’s latest output, replacing the previous view. While watch with -d can highlight new entries, it only shows a snapshot, not a continuous historical stream like tail -f. Choose tail -f for continuous log monitoring where history is crucial, and watch for refreshing snapshots, especially with highlighting for quick change detection.

