getent

Query the name service the rest of the system uses

Updated 2026-09-28

getent asks the Name Service Switch for an entry and prints it in the format of the file that database is modelled on. On a default Debian install the file is the only source, so getent passwd tips-ops prints the same line as grep '^tips-ops:' /etc/passwd. Once accounts also come from LDAP, Active Directory or systemd-homed, the file holds only the local ones: getent still finds the rest, and the grep finds nothing, without an error to say why.

Which sources are consulted, and in what order, is governed by /etc/nsswitch.conf. getent reads it the way every other program on the system does, so a script that uses it sees the accounts a login or a service would see. One that greps the file works on the machine it was written on and finds nothing on a machine whose accounts live somewhere else.

The databases go well beyond accounts. hosts, services and protocols are the other three worth knowing, and each saves opening a file under /etc and reading it by eye.

Sample files used on this page

Every example below was run against these files. Recreate them to follow along.

the accounts, and a host that exists only in /etc/hosts The same accounts as id, and the first two are the ones managing-users starts from, so the three pages name the same people. tips-ops holds tips-deploy as a supplementary group and tips-site holds it as its primary one, which is the difference the group listing below does not show. backup.example.com is in /etc/hosts and no DNS server has a record for it: example.com is reserved by RFC 2606 and 192.0.2.0/24 by RFC 5737, so the name cannot collide with a real host and the address cannot route to one.

tips-dev:x:1001:1001:Deployment account:/home/tips-dev:/bin/bash
tips-ops:x:1002:1002:Operations account:/home/tips-ops:/bin/bash
tips-site:x:1010:4000:Website account:/home/tips-site:/bin/bash
tips-deploy:x:4000:tips-ops
192.0.2.10  backup.example.com backup
13 outputs, collapsed by default

Looking up an account or a group

The passwd and group databases print a record in the format of the file they are named after, colons and all. The key may be the name or the number.

Read one account's record

getent passwd tips-ops

Name, password placeholder, uid, primary gid, description, home directory, shell. The x is not a password: it means the hash lives in /etc/shadow, which is a separate database with separate permissions.

Show output
tips-ops:x:1002:1002:Operations account:/home/tips-ops:/bin/bash

Look an account up by its number

getent passwd 1002

Numeric keys work on every database that has them, so this puts a name to a uid in output that carries bare numbers. id -un does the same lookup and prints only the name.

Show output
tips-ops:x:1002:1002:Operations account:/home/tips-ops:/bin/bash

Read a group's membership

getent group tips-deploy

The fourth field is the member list. Membership is recorded here, on the group, and an account's own record has no field naming its supplementary groups, so finding every group one account is in means walking every group. id -G does that walk for you.

Show output
tips-deploy:x:4000:tips-ops

Look up a key that doesn't exist

getent passwd nosuchuser; echo "exit $?"

Nothing on standard output and status 2, which is the number to test for: it is what separates a key that is not there from a misspelled database, which the next example shows exiting 1.

Show output
exit 2

Look up a database that doesn't exist

getent nosuchdb tips-ops 2>&1; echo "exit $?"

Status 1 rather than 2, so the two failures are distinguishable. It is the typo case: the database is group, and getent groups stops here with this message.

Show output
Unknown database: nosuchdb
Try `getent --help' or `getent --usage' for more information.
exit 1

Where a result comes from, and who may read it

getent is a thin wrapper over the same library calls every other program makes, so it consults the sources named in /etc/nsswitch.conf in the order written there.

See where each database looks things up

grep -E "^(passwd|group|hosts):" /etc/nsswitch.conf

A stock Debian install answers accounts from files alone, and hostnames from the file first and DNS after. Joining a machine to LDAP or Active Directory adds a source to these lines, and, from then on, a grep of /etc/passwd only sees a fraction of the accounts.

Show output
passwd:         files
group:          files
hosts:          files dns

Force one source and skip the rest

getent -s files passwd tips-ops

-s overrides nsswitch.conf for this call only. Requesting files explicitly is how to find out whether an account is local or comes from the directory, without editing anything or restarting a service.

Show output
tips-ops:x:1002:1002:Operations account:/home/tips-ops:/bin/bash

Prove the file was skipped

getent -s dns hosts backup.example.com; echo "exit $?"

The name is only in /etc/hosts, as the fixture above shows, and no DNS server has a record for it, so a lookup restricted to DNS finds nothing. /etc/hosts was never read.

Show output
exit 2

Read the shadow database as root and as anybody else

getent shadow tips-dev | cut -d: -f1,2; runuser -u user -- getent shadow tips-dev; echo "exit $?"

Trimmed to the first two fields because the rest are day counts that move. ! is a locked password. The second call makes the same lookup as an ordinary account and gets status 2, the same result as for a name that does not exist. /etc/shadow is mode 640, owned by root and group shadow, so the lookup cannot open the file and reports finding nothing rather than being refused.

Show output
tips-dev:!
exit 2

Members a group listing leaves out

A group's fourth field names the accounts that hold it as a supplementary group. An account whose primary group it is has the membership recorded on its own record instead, and appears in neither field the other one prints.

Find the member the group does not mention

getent passwd tips-site; id -Gn tips-site

The fourth field of the account record is 4000, which is tips-deploy, and getent group tips-deploy above lists only tips-ops. Auditing a group by reading its member list therefore misses everyone who was added with adduser --ingroup, and id is the command that does not.

Show output
tips-site:x:1010:4000:Website account:/home/tips-site:/bin/bash
tips-deploy users

The databases that are not about accounts

Anything with a file under /etc and a lookup function in the C library is reachable here, which saves guessing at a format or remembering a path.

Resolve a hostname the way the system does

getent hosts backup.example.com

Address first, then every name the entry carries. This follows nsswitch.conf, so it sees /etc/hosts and returns what a program connecting to the name would get, which a tool that queries DNS directly cannot. getent ahosts asks through getaddrinfo instead and reports every address family and socket type separately.

Show output
192.0.2.10      backup.example.com backup

Put a number to a service name, or the reverse

getent services ssh; getent services 80/tcp

Either direction, from /etc/services. Handy when reading firewall rules or ss output that has been left numeric, and quicker than searching a file of three hundred-odd entries by eye.

Show output
ssh                   22/tcp
http                  80/tcp www

Put a number to a protocol

getent protocols tcp

The number an IP header carries to say what follows it, and the table iptables -p tcp consults to turn the name into it. 6 for TCP, 17 for UDP, 1 for ICMP.

Show output
tcp                   6 TCP