Find the largest files on disk
du, sort and head, aimed at any directory
Problem: Disk space is running low and you need to find out what's using it.
df -h is what told you, and it reports per filesystem; everything below
narrows that down to a directory and then to a file.
Solution:
du -ah projects | sort -rh | head -6
6.1M projects/logs
6.1M projects
6.0M projects/logs/big.log
20K projects/src
20K projects/backups
12K projects/logs/app.log
How it works:
du -ah projectsprints the disk usage of every file and directory underneath it, in human-readable sizes (-h), including individual files, not just directory totals (-a). See du for what that number measures. Point it at/varor/for the real investigation; a small tree is used here so the numbers on this page are ones you can reproduce.sort -rhsorts that output by size, largest first (-rreverse,-hunderstands human-readable sizes like "1.2G"). See sort for more, including the common mistake of using-hwithout also telling it which field to sort by.head -6keeps just the top of the ranking (see head). Usehead -20on a real filesystem, where there is far more to sift through.
Note that directories and their contents both appear: projects/logs at 6.1M is the directory
holding big.log at 6.0M, not a second copy of it. -a was asked for every file, so the totals
down the column add up to more than the disk holds.
Variations:
du -ah . | sort -rh | head -20 # current directory instead of the whole filesystem
du -sh */ # top-level directories only, not every file
find /var -size +500k -exec ls -lh {} \; # only files over a size threshold
Restricting to top-level directories first (du -sh */) is often the faster starting point on
a large filesystem: it tells you which subtree to dig into with the full du -ah command,
rather than sorting through every individual file up front.
If the culprit turns out to be an old backup archive rather than a single runaway file, look
inside it before deleting: tar -tzvf backup.tar.gz lists contents with sizes without
extracting anything (see tar).
For repeated disk investigations, ncdu (not installed by default; apt install ncdu) gives
the same information as the du command above and lets you walk the tree, instead of re-running
the command with a different path each time.