This post was originally published on go2linux.org. The domain is no longer mine, but I am the original author. I am republishing it here on garron.me with corrections and improvements.

dmesg prints the kernel ring buffer: the messages the Linux kernel writes while booting and while running. It is the first place to look when a disk, a USB device, a network card or a driver misbehaves.

Basic usage

sudo dmesg

The output is long, so pipe it to a pager or let dmesg do it with -H:

sudo dmesg | less
sudo dmesg -H

-H enables human-readable output: a pager, colors, and relative timestamps.

"Operation not permitted"

On current Debian, Ubuntu and many other distributions, a regular user gets this:

dmesg: read kernel buffer failed: Operation not permitted

Kernel messages can leak memory addresses and other details useful to an attacker, so access is restricted by the kernel.dmesg_restrict setting. Use sudo, as in the examples of this article.

To check the setting:

sysctl kernel.dmesg_restrict

A value of 1 means only root can read the buffer. You can set it to 0 on a personal machine, but leave it alone on servers and shared systems.

Readable timestamps

By default each line starts with the number of seconds since boot:

[    2.418337] usb 1-1: new high-speed USB device number 2 using xhci_hcd

-T converts that to a date and time:

sudo dmesg -T
[Mon Oct  5 09:14:02 2026] usb 1-1: new high-speed USB device number 2 using xhci_hcd

These times are calculated from the boot time, and the kernel clock does not advance while the machine is suspended. On a laptop that has slept, -T timestamps can be off; for exact times use journalctl -k (see below).

Show only errors and warnings

Every kernel message has a level. -l filters by one or more of them:

sudo dmesg -l err,warn

The levels, from most to least severe, are emerg, alert, crit, err, warn, notice, info and debug.

To see the level and facility of each line, add -x:

sudo dmesg -x

Filter by facility

-f selects the source of the message. The most useful distinction is kernel versus userspace:

sudo dmesg -f kern
sudo dmesg -f daemon

-k and -u are shortcuts for kernel-only and userspace-only messages.

Follow new messages live

-w keeps dmesg running and prints new messages as they arrive, like tail -f:

sudo dmesg -w

Run it, then plug in a USB drive: you will see the kernel detect the device and assign it a name such as sdb. Use -W instead to skip the existing buffer and show only what happens from now on.

Search for something

dmesg combines well with grep:

sudo dmesg | grep -i usb
sudo dmesg | grep -i -E 'sd[a-z]|nvme'
sudo dmesg | grep -i -E 'eth|enp|wlan|link is'

Check whether the kernel killed a process for lack of memory:

sudo dmesg -T | grep -i -E 'out of memory|killed process'

Look for disk trouble:

sudo dmesg -T -l err,warn | grep -i -E 'ata|i/o error|ext4|xfs'

Save the messages to a file

Handy when you need to send the boot log to someone who is helping you:

sudo dmesg -T > boot-messages.txt

Clear the buffer

-C empties the ring buffer; -c prints it first and then empties it:

sudo dmesg -C

This is useful before a test: clear the buffer, reproduce the problem, and what is left is only what the problem produced. The messages already stored in the system journal are not affected.

The buffer has a fixed size

It is called a ring buffer because it has a fixed size and new messages overwrite the oldest ones. On a machine that has been up for weeks, or one with a chatty driver, the boot messages may already be gone from dmesg.

journalctl -k

On systems with systemd, the journal stores the kernel messages on disk, with accurate timestamps, and keeps them across reboots:

journalctl -k

Kernel messages from the previous boot — very useful after a crash:

journalctl -k -b -1

Follow live, or show only errors:

journalctl -k -f
journalctl -k -p err

Use dmesg for a quick look at what the kernel is saying right now, and journalctl -k when you need history or precise times.

See also

man dmesg — full reference.