iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Use dmesg to inspect messages in the Linux kernel ring buffer, including messages about boot and hardware. Its options can filter and format the output, follow new messages, or clear the buffer. For kernel logs from an earlier boot on a systemd machine, use journalctl instead—if the journal retained those records.
What dmesg shows—and what it cannot prove
The upstream util-linux dmesg manual describes the command this way: “dmesg is used to examine or control the kernel ring buffer.” With no options, dmesg displays the messages currently available there. That makes it useful for checking kernel activity, but a warning or error is a clue to investigate, not proof of a root cause.
The ring buffer is not the same as a complete archive of every boot. If you need older records, a systemd journal may have them; whether it does depends on what was collected and retained. Available dmesg options also vary with the installed util-linux version and distribution build. Check dmesg --help before relying on a particular option.
Free tools Windows power users keep installed
One-click scans. No signup required.
12 useful command patterns
1. Display available kernel messages
dmesg
Start here for a broad view of messages currently available in the kernel ring buffer. Look for text related to the symptom, device, or time of failure. Output volume and the messages available depend on the system and its current buffer.
#1 Best Overall
2. Follow new messages
dmesg --follow
When supported and permitted, this waits for new messages and prints them as they arrive. Start it before reproducing an issue—for example, connecting a device—and watch for messages that coincide with the event. It requires readable /dev/kmsg support.
3. Show errors and warnings
dmesg --level=err,warn
This limits output to the error and warning priorities where the installed version supports --level. Use it to reduce noise, then inspect the surrounding messages or broader output if the filtered view does not explain the symptom. Filtering by severity can omit context that matters.
4. Limit output to the kernel facility
dmesg --facility=kern
Where supported, this selects messages associated with the kernel facility. It can help narrow a mixed view while investigating kernel activity; it does not by itself establish which message caused a problem.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Rank #2
5. Decode facility and priority
dmesg --decode
This requests human-readable facility and priority names instead of relying on numeric values, where the option is available. It can make message metadata easier to scan alongside the message text.
6. Use human-readable output
dmesg --human
On builds that support it, this requests human-readable output and pager behavior. It can be more convenient for browsing a long listing. Confirm the option and its behavior with local help.
7. Show time deltas between messages
dmesg --show-delta
Where supported, this adds the elapsed time between messages. Deltas can help identify a cluster of messages around a slowdown, device failure, or other event. They show intervals in the message sequence, not an independently verified event timeline.
Rank #3
8. Show relative time with local-time context
dmesg --reltime
This requests local-time and delta information where supported. Treat converted wall-clock times cautiously: the upstream manual documents accuracy caveats for human-readable timestamp conversion. Do not treat the displayed local time as a guaranteed exact event time.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problems9. Request ISO-style timestamps
dmesg --time-format=iso
Where available, this requests ISO-style timestamps. The accepted formats can vary by installed version, so consult dmesg --help if the option is rejected or behaves differently than expected. Timestamp formatting changes how time is presented; it does not make a converted timestamp exact.
10. Clear the ring buffer only when appropriate
dmesg --clear
This clears the kernel ring buffer where supported. Clearing changes diagnostic state and may remove messages you still need to inspect. Do not run it casually when preserving evidence or comparing later output matters.
Rank #4
11. Read supported syslog-format messages from a file
dmesg --file FILE
Where supported, this reads messages from a file in a supported syslog format. The upstream manual notes that this mode does not support kmsg-format messages. The uppercase FILE here represents a path you supply; it is not a literal filename.
12. Query kernel messages from the previous boot
journalctl -k -b -1
This is a journalctl command, not a dmesg option. On a systemd system, -k selects kernel messages and -b -1 selects the previous boot. It can help investigate an issue that happened before the current boot, but only if the journal collected and retained the relevant records. See the journalctl manual for kernel and boot-selection options.
How to use dmesg to investigate a problem
-
Run
dmesgfor a read-only first look at messages currently available in the ring buffer. -
Narrow the view using a supported priority or facility option, or search the output for a device name or recognizable message text.
-
Check the message sequence and, if useful, time deltas around when the symptom began. For a device problem, compare messages with the moment the device was connected or failed.
-
If you can read new messages, run
dmesg --followwhile reproducing the issue. Look for messages that coincide with the event, then interpret them alongside the observed symptoms and other logs.Recommended: Crashes or Glitches? A Free Driver Scan Usually Finds the Culprit →Recommended: Fix Windows Errors and Clear Junk Files in Minutes - Free Scan →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
If the event occurred before the current boot, try
journalctl -k -b -1and select the relevant boot or records. This works only when the journal contains the needed history.
What to do if dmesg says access is denied
The current dmesg manual says access denial is usually caused by the kernel dmesg_restrict setting. This is a system policy, not a reason to disable a restriction automatically. Ask an authorized administrator to assess the policy and determine whether access is appropriate; do not treat changing it as a routine troubleshooting step.
dmesg or journalctl for kernel logs?
| Question | dmesg |
journalctl -k -b -1 |
|---|---|---|
| Source and scope | Messages available in the current kernel ring buffer. | Kernel messages collected in the systemd journal for the selected boot. |
| Time coverage | Current ring-buffer contents. | Can select a previous boot if its records were collected and retained. |
| Useful filtering | Options can filter by message priority or facility where supported. | -k selects kernel messages; boot selection and other journal filters can narrow records. |
| Dependency | Requires permitted access to the kernel buffer; readable /dev/kmsg is needed for following new messages. |
Requires systemd journal records for the boot and period you want to inspect. |
These commands serve different needs: dmesg inspects the current ring buffer, while the journal can provide retained history. Neither is a universal substitute for the other.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.

