The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect a device | udevadm info --query=all --name=/dev/sdb | View examples |
| Walk parent attributes | udevadm info --attribute-walk --name=/dev/sdb | View examples |
| Resolve sysfs path | udevadm info --query=path --name=/dev/sdb | View examples |
| Monitor kernel and udev events | udevadm monitor --kernel --udev --property | View examples |
| Filter event monitoring | udevadm monitor --udev --property \
--subsystem-match=block | View examples |
| Verify rule syntax | udevadm verify /etc/udev/rules.d/70-backup-disk.rules | View examples |
| Test rule evaluation | udevadm test --action=add /sys/class/block/sdb | View examples |
| Test a builtin | udevadm test-builtin blkid /sys/class/block/sdb | View examples |
| Reload rules | sudo udevadm control --reload | View examples |
| Preview a trigger scope | udevadm trigger --dry-run --verbose \
--subsystem-match=block | View examples |
| Retrigger one device | sudo udevadm trigger --action=change \
/sys/class/block/sdb | View examples |
| Check the event queue | udevadm settle --timeout=10 | View examples |
| Read udev daemon logs | journalctl --unit=systemd-udevd --boot --no-pager | View examples |
| Export the udev database | udevadm info --export-db | View examples |
udev receives kernel device events, enriches them with properties, manages device-node metadata, and creates stable links used by services. Reliable rules match immutable device identity rather than discovery order, perform only short event-time work, and integrate long-running actions with systemd. Observe a real event and test the exact sysfs device before deploying any rule that changes permissions or triggers services.
Step by step
Detailed examples
Start from stable identity in the udev database and sysfs
A /dev name such as /dev/sdb can change with enumeration order. Query the device's udev properties and walk its sysfs parents to find serial, WWN, vendor, product, or topology attributes that remain stable. Match attributes from one parent level consistently: a single rule cannot combine ATTRS values from different ancestor devices as though they came from the same parent.
udevadm info --query=all --name=/dev/sdb
udevadm info --query=path --name=/dev/sdb
udevadm info --attribute-walk --name=/dev/sdb Observe kernel input and processed udev output separately
Kernel events arrive before udev has imported properties or applied rules. Monitoring both streams reveals the action, subsystem, device path, sequence, and final properties. Reproduce attachment or removal only when operationally safe; disconnecting storage, network, or input devices can interrupt the host. Filter by subsystem to reduce noise without assuming every relevant parent shares that subsystem.
udevadm monitor --kernel --udev --property --subsystem-match=block
# In another approved session, attach the test device and compare KERNEL with UDEV records. Write narrow rules that add stable names instead of renaming kernel devices
Rule files end in .rules and are processed lexically across vendor and administrator directories. Match ACTION and SUBSYSTEM first, then immutable identity. Prefer SYMLINK+= to provide an application-facing name while retaining the kernel name. Use TAG+="systemd" and SYSTEMD_WANTS for service integration; do not run long, networked, or daemonized work through RUN because event workers have strict lifecycle constraints.
# /etc/udev/rules.d/70-backup-disk.rules
ACTION=="add|change", SUBSYSTEM=="block", ENV{DEVTYPE}=="disk", ENV{ID_SERIAL_SHORT}=="S3Z9EXAMPLE", SYMLINK+="backup-disk"
# Avoid MODE="0666"; grant the narrow group or service access actually required. Verify syntax and simulate the exact sysfs device
udevadm verify catches syntax, quoting, and compatibility problems in supported versions. udevadm test explains which files and rules match a sysfs path, but simulation is not a perfect substitute for a real kernel event and some builtins can observe or update state. Use a disposable test device, read the full diagnostic output, and confirm the expected property or symlink assignment before reloading production rules.
udevadm verify /etc/udev/rules.d/70-backup-disk.rules
udevadm test --action=add /sys/class/block/sdb
udevadm test-builtin blkid /sys/class/block/sdb Reload for future events and retrigger only a reviewed scope
Reloading updates the rule set but does not apply it to devices already present. Preview a trigger selection before emitting synthetic events, then target one known sysfs path when possible. Retriggering a broad subsystem can alter links, ownership, network naming, or service activation across the host; schedule and monitor it like any other production change.
sudo udevadm control --reload
udevadm trigger --dry-run --verbose --subsystem-match=block
# After reviewing the target, retrigger only that device:
sudo udevadm trigger --action=change /sys/class/block/sdb Diagnose rules, daemon health, and downstream service ordering
If a property or link is missing, confirm the event occurred, the rule filename and match keys are correct, and no later assignment overrides it. Check systemd-udevd logs and the stored database record. udevadm settle waits only for the present queue and does not guarantee that all hardware discovery is complete; services should bind to specific device units or events instead of globally delaying boot.
udevadm info --query=all --name=/dev/sdb
udevadm settle --timeout=10
journalctl --unit=systemd-udevd --boot --no-pager
systemctl status dev-backup\x2ddisk.device --no-pager Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



