# Disk full: find what fills it and free space safely

> Fix No space left on device on Linux and full drives on Windows Server: find large folders, clean logs, caches and old packages, and handle inodes.

Difficulty: Beginner\
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows Server 2022, Windows Server 2025

When a disk fills up, databases stop writing, websites throw errors, mail queues stall and sometimes you cannot even log in. This guide finds what is using the space and frees it safely, on Linux and on Windows Server.

## Before you start

- Log in over SSH, or through the web console if your service page shows one; a completely full disk can break SSH logins.
- Do not delete files you do not recognise. Look first, then remove what you are sure about.

## Step 1: Confirm the disk is full

```bash
df -h
df -i
```

`df -h` shows space per file system; look for `Use%` near 100 on `/` or on a data mount. `df -i` shows **inodes**: if `IUse%` is at 100 while space is free, you have too many small files.

## Step 2: Find the large folders

Start at the root and drill down into the biggest folder each time. `-x` stays on one file system:

```bash
sudo du -xh --max-depth=1 / 2>/dev/null | sort -h | tail -n 15
sudo du -xh --max-depth=1 /var 2>/dev/null | sort -h | tail -n 15
```

`ncdu` does the same interactively (`sudo apt install ncdu`, then `sudo ncdu -x /`). To list single large files:

```bash
sudo find / -xdev -type f -size +500M -exec ls -lh {} + 2>/dev/null
```

**Verify:** you now know which folder holds the space. The usual suspects are below.

## Step 3: Free space safely

### The systemd journal

```bash
journalctl --disk-usage
sudo journalctl --vacuum-size=200M
```

To keep it small permanently, set `SystemMaxUse=200M` in `/etc/systemd/journald.conf` and run `sudo systemctl restart systemd-journald`.

### Old logs

Rotated logs in `/var/log` (files ending in `.1`, `.gz`) can be deleted. Do not delete an active log a service is writing to; empty it instead:

```bash
sudo truncate -s 0 /var/log/nginx/access.log
```

Then check that `logrotate` rotates that log, so it does not grow back.

### Package caches and old kernels

```bash
sudo apt clean
sudo apt autoremove --purge
```

`apt autoremove` removes packages that are no longer needed, including old kernels. Read the list it shows before confirming.

### Docker

Images, stopped containers and build caches can take many gigabytes:

```bash
docker system df
docker system prune
```

`docker system prune` removes stopped containers, unused networks, dangling images and build cache. It asks before it deletes; do not add `--volumes` unless you are sure no volume holds data you need.

### Backups and dumps on the server

Old backup archives and database dumps are a common cause. Move them off the server, then delete them locally. Backups stored on the same disk do not protect you anyway; see [backup strategy](/guides/backup-strategy-3-2-1).

### Too many small files (inodes)

Find the folder with the most files:

```bash
sudo find / -xdev -type f 2>/dev/null | cut -d/ -f2-3 | sort | uniq -c | sort -n | tail -n 10
```

PHP sessions, cache folders and mail queues are typical. Clean them with the tool of the application if it has one.

## Step 4: Deleted, but the space did not come back

A process still holds the deleted file open:

```bash
sudo lsof +L1
```

The output names the process. Restart that service (for example `sudo systemctl restart nginx`) to release the space.

## Windows Server

- Check free space with `Get-Volume` in PowerShell or in File Explorer.
- Find large folders with File Explorer's search (`size:>1GB`) or a disk usage tool.
- Run **Disk Cleanup** (`cleanmgr`) and choose **Clean up system files**, where it is available.
- Clean up the component store (WinSxS) after updates:

```powershell
Dism.exe /Online /Cleanup-Image /StartComponentCleanup
```

- Check IIS logs in `C:\inetpub\logs\LogFiles` and old SQL Server backups.

## Prevent it next time

- Keep log rotation and journal limits in place.
- Store backups on another system.
- Set up monitoring that warns you at around 80 percent disk usage.
- If the server simply needs more room, move to a bigger plan and extend the file system: see [upgrade or downgrade a service](/guides/upgrade-or-downgrade-service).

## When to open a ticket

If the server cannot boot because the disk is full, or `df` reports errors, open a ticket with the server selected and the output of `df -h` and `df -i` if you can get it.

## Next steps

- Other resource problems: [high CPU or memory usage](/guides/high-cpu-memory).
- Grow the disk: [upgrade or downgrade a service](/guides/upgrade-or-downgrade-service).

## Frequently asked questions

### df shows free space, but I still get No space left on device. Why?

The file system has run out of inodes, the entries that track files, usually because of millions of tiny files such as sessions or cache files. Check with df -i and delete the small files that piled up.

### I deleted a large file, but the space did not come back. Why?

A running process still has the file open, so the space is only released when the process closes it. Find such files with lsof +L1 and restart the process that holds them.

### Is it safe to delete files in /var/log?

Old rotated logs, such as files ending in .gz or .1, are safe to delete. Do not delete the active log files; truncate them instead, or limit the systemd journal with journalctl --vacuum-size.

### Can I make my disk bigger?

Yes, by moving to a plan with a larger disk or adding disk space where your plan offers it. After an upgrade, extend the partition and file system so the server can use the new space.

### How can I avoid this next time?

Keep log rotation and journal limits in place, move backups off the server, clean up old releases and caches regularly, and watch disk usage with a monitoring alert.

---

Source: <https://hyperdc.com/guides/troubleshooting/disk-full>\
Updated: 2026-10-09
