Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Use dmesg to inspect messages in the Linux kernel ring buffer, including messages about boot and hardware. Its options can filter and format the output, follow new messages, or clear the buffer. For kernel logs from an earlier boot on a systemd machine, use journalctl instead—if the journal retained those records.

What dmesg shows—and what it cannot prove

The upstream util-linux dmesg manual describes the command this way: “dmesg is used to examine or control the kernel ring buffer.” With no options, dmesg displays the messages currently available there. That makes it useful for checking kernel activity, but a warning or error is a clue to investigate, not proof of a root cause.

The ring buffer is not the same as a complete archive of every boot. If you need older records, a systemd journal may have them; whether it does depends on what was collected and retained. Available dmesg options also vary with the installed util-linux version and distribution build. Check dmesg --help before relying on a particular option.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

12 useful command patterns

1. Display available kernel messages

dmesg

Start here for a broad view of messages currently available in the kernel ring buffer. Look for text related to the symptom, device, or time of failure. Output volume and the messages available depend on the system and its current buffer.

2. Follow new messages

dmesg --follow

When supported and permitted, this waits for new messages and prints them as they arrive. Start it before reproducing an issue—for example, connecting a device—and watch for messages that coincide with the event. It requires readable /dev/kmsg support.

3. Show errors and warnings

dmesg --level=err,warn

This limits output to the error and warning priorities where the installed version supports --level. Use it to reduce noise, then inspect the surrounding messages or broader output if the filtered view does not explain the symptom. Filtering by severity can omit context that matters.

4. Limit output to the kernel facility

dmesg --facility=kern

Where supported, this selects messages associated with the kernel facility. It can help narrow a mixed view while investigating kernel activity; it does not by itself establish which message caused a problem.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

5. Decode facility and priority

dmesg --decode

This requests human-readable facility and priority names instead of relying on numeric values, where the option is available. It can make message metadata easier to scan alongside the message text.

6. Use human-readable output

dmesg --human

On builds that support it, this requests human-readable output and pager behavior. It can be more convenient for browsing a long listing. Confirm the option and its behavior with local help.

7. Show time deltas between messages

dmesg --show-delta

Where supported, this adds the elapsed time between messages. Deltas can help identify a cluster of messages around a slowdown, device failure, or other event. They show intervals in the message sequence, not an independently verified event timeline.

8. Show relative time with local-time context

dmesg --reltime

This requests local-time and delta information where supported. Treat converted wall-clock times cautiously: the upstream manual documents accuracy caveats for human-readable timestamp conversion. Do not treat the displayed local time as a guaranteed exact event time.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

9. Request ISO-style timestamps

dmesg --time-format=iso

Where available, this requests ISO-style timestamps. The accepted formats can vary by installed version, so consult dmesg --help if the option is rejected or behaves differently than expected. Timestamp formatting changes how time is presented; it does not make a converted timestamp exact.

10. Clear the ring buffer only when appropriate

dmesg --clear

This clears the kernel ring buffer where supported. Clearing changes diagnostic state and may remove messages you still need to inspect. Do not run it casually when preserving evidence or comparing later output matters.

11. Read supported syslog-format messages from a file

dmesg --file FILE

Where supported, this reads messages from a file in a supported syslog format. The upstream manual notes that this mode does not support kmsg-format messages. The uppercase FILE here represents a path you supply; it is not a literal filename.

12. Query kernel messages from the previous boot

journalctl -k -b -1

This is a journalctl command, not a dmesg option. On a systemd system, -k selects kernel messages and -b -1 selects the previous boot. It can help investigate an issue that happened before the current boot, but only if the journal collected and retained the relevant records. See the journalctl manual for kernel and boot-selection options.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to use dmesg to investigate a problem

  1. Run dmesg for a read-only first look at messages currently available in the ring buffer.

  2. Narrow the view using a supported priority or facility option, or search the output for a device name or recognizable message text.

  3. Check the message sequence and, if useful, time deltas around when the symptom began. For a device problem, compare messages with the moment the device was connected or failed.

  4. If you can read new messages, run dmesg --follow while reproducing the issue. Look for messages that coincide with the event, then interpret them alongside the observed symptoms and other logs.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  5. If the event occurred before the current boot, try journalctl -k -b -1 and select the relevant boot or records. This works only when the journal contains the needed history.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to do if dmesg says access is denied

The current dmesg manual says access denial is usually caused by the kernel dmesg_restrict setting. This is a system policy, not a reason to disable a restriction automatically. Ask an authorized administrator to assess the policy and determine whether access is appropriate; do not treat changing it as a routine troubleshooting step.

dmesg or journalctl for kernel logs?

Question dmesg journalctl -k -b -1
Source and scope Messages available in the current kernel ring buffer. Kernel messages collected in the systemd journal for the selected boot.
Time coverage Current ring-buffer contents. Can select a previous boot if its records were collected and retained.
Useful filtering Options can filter by message priority or facility where supported. -k selects kernel messages; boot selection and other journal filters can narrow records.
Dependency Requires permitted access to the kernel buffer; readable /dev/kmsg is needed for following new messages. Requires systemd journal records for the boot and period you want to inspect.

These commands serve different needs: dmesg inspects the current ring buffer, while the journal can provide retained history. Neither is a universal substitute for the other.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.