This post was originally published on go2linux.org. The domain is no longer mine, but I am the original author. I am republishing it here on garron.me with corrections and improvements.
dmesg prints the kernel ring buffer: the messages the Linux kernel writes while booting and while running. It is the first place to look when a disk, a USB device, a network card or a driver misbehaves.
Basic usage
sudo dmesg
The output is long, so pipe it to a pager or let dmesg do it with -H:
sudo dmesg | less
sudo dmesg -H
-H enables human-readable output: a pager, colors, and relative timestamps.
"Operation not permitted"
On current Debian, Ubuntu and many other distributions, a regular user gets this:
dmesg: read kernel buffer failed: Operation not permitted
Kernel messages can leak memory addresses and other details useful to an attacker, so access is restricted by the kernel.dmesg_restrict setting. Use sudo, as in the examples of this article.
To check the setting:
sysctl kernel.dmesg_restrict
A value of 1 means only root can read the buffer. You can set it to 0 on a personal machine, but leave it alone on servers and shared systems.
Readable timestamps
By default each line starts with the number of seconds since boot:
[ 2.418337] usb 1-1: new high-speed USB device number 2 using xhci_hcd
-T converts that to a date and time:
sudo dmesg -T
[Mon Oct 5 09:14:02 2026] usb 1-1: new high-speed USB device number 2 using xhci_hcd
These times are calculated from the boot time, and the kernel clock does not advance while the machine is suspended. On a laptop that has slept, -T timestamps can be off; for exact times use journalctl -k (see below).
Show only errors and warnings
Every kernel message has a level. -l filters by one or more of them:
sudo dmesg -l err,warn
The levels, from most to least severe, are emerg, alert, crit, err, warn, notice, info and debug.
To see the level and facility of each line, add -x:
sudo dmesg -x
Filter by facility
-f selects the source of the message. The most useful distinction is kernel versus userspace:
sudo dmesg -f kern
sudo dmesg -f daemon
-k and -u are shortcuts for kernel-only and userspace-only messages.
Follow new messages live
-w keeps dmesg running and prints new messages as they arrive, like tail -f:
sudo dmesg -w
Run it, then plug in a USB drive: you will see the kernel detect the device and assign it a name such as sdb. Use -W instead to skip the existing buffer and show only what happens from now on.
Search for something
dmesg combines well with grep:
sudo dmesg | grep -i usb
sudo dmesg | grep -i -E 'sd[a-z]|nvme'
sudo dmesg | grep -i -E 'eth|enp|wlan|link is'
Check whether the kernel killed a process for lack of memory:
sudo dmesg -T | grep -i -E 'out of memory|killed process'
Look for disk trouble:
sudo dmesg -T -l err,warn | grep -i -E 'ata|i/o error|ext4|xfs'
Save the messages to a file
Handy when you need to send the boot log to someone who is helping you:
sudo dmesg -T > boot-messages.txt
Clear the buffer
-C empties the ring buffer; -c prints it first and then empties it:
sudo dmesg -C
This is useful before a test: clear the buffer, reproduce the problem, and what is left is only what the problem produced. The messages already stored in the system journal are not affected.
The buffer has a fixed size
It is called a ring buffer because it has a fixed size and new messages overwrite the oldest ones. On a machine that has been up for weeks, or one with a chatty driver, the boot messages may already be gone from dmesg.
journalctl -k
On systems with systemd, the journal stores the kernel messages on disk, with accurate timestamps, and keeps them across reboots:
journalctl -k
Kernel messages from the previous boot — very useful after a crash:
journalctl -k -b -1
Follow live, or show only errors:
journalctl -k -f
journalctl -k -p err
Use dmesg for a quick look at what the kernel is saying right now, and journalctl -k when you need history or precise times.
See also
man dmesg — full reference.