Inventory Linux Hardware with lshw Without Leaking Serial Numbers
You will finish with a repeatable way to inspect a Linux machine's hardware, narrow the result to a useful class, and save a report in a format another tool can process. You will also know when the command needs root and how to remove sensitive values before sharing output.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes. You need a shell and the lshw package. The examples use lshw package version 02.19.git.2021.06.19.996aaad9c7-2ubuntu0.24.04.1, installed on Ubuntu 24.04 in this environment. Hardware names, paths and values will differ on your machine.
1. Confirm the installed command
Start with read-only checks. These do not need elevated privileges:
$ command -v lshw
/usr/bin/lshw
$ dpkg-query -W -f='${Package} ${Version}\n' lshw
lshw 02.19.git.2021.06.19.996aaad9c7-2ubuntu0.24.04.1
$ lshw -version
Hardware Lister (lshw) -
The final line identifies the program, but this build does not print a useful version number after the hyphen. The package query is the reliable version check here. If your distribution uses a different package manager, use its installed-package query and keep the command's own -version result for comparison.
Checkpoint: you have confirmed which binary will collect the inventory and recorded its package version.
2. Run a compact first scan
Use -short for a quick hardware tree. It shows paths, device names, classes and descriptions without the detail of the default report:
$ sudo lshw -short
H/W path Device Class Description
==================================================
system Computer
/0 bus Motherboard
/0/0 memory 32GiB System memory
/0/1 processor Intel(R) Core(TM) i7-7700 CPU @ 3.60GHz
/0/100/2 display HD Graphics 630
Your output is host-specific. The command may print a warning when it is not run as superuser, and the manual says non-root runs report only partial information. Treat a partial scan as a clue, not a complete inventory.
Do not assume the path or description identifies a physical part uniquely. Virtual machines, firmware tables and kernel device exposure all affect what lshw can see. Its local manual also lists incomplete support for some architectures and says FireWire devices are not currently detected.
3. Narrow the report to one hardware class
Use -class when the full tree is distracting. The class name comes from the output of -short or -businfo. This example selects disks and storage controllers:
$ sudo lshw -class disk -class storage
*-sata
description: SATA controller
product: Q170/Q150/B150/H170/H110/Z170/CM236 Chipset SATA Controller [AHCI Mode]
vendor: Intel Corporation
physical id: 17
bus info: pci@0000:00:17.0
Repeat -class to request more than one class. The short aliases -C and -c are also accepted, but the long form is easier to read in a script. Common classes include memory, processor, network, storage, disk, display and usb. Do not treat that list as an exhaustive enumeration: use the classes your own scan reports.
Checkpoint: if a full scan is too noisy, choose a class from your own output and rerun with root privileges.
4. Choose a format for the job
Keep the default text output for a person reading a diagnostic record. Use -businfo when addresses matter:
$ sudo lshw -businfo
Bus info Device Class Description
=======================================================
cpu@0 processor Intel(R) Core(TM) i7-7700 CPU @ 3.60GHz
pci@0000:00:17.0 storage SATA controller
For scripts, request -json or -xml. Both describe the device tree; JSON is usually the more convenient starting point for shell-adjacent tooling:
$ sudo lshw -json -notime > hardware.json
$ test -s hardware.json && echo 'JSON report written'
JSON report written
-notime removes volatile timestamp attributes, which makes repeated reports easier to compare. -numeric adds numeric PCI and USB IDs alongside names, useful when a name is ambiguous or a local ID database is incomplete. It does not turn the report into a stable hardware fingerprint.
5. Sanitise before sharing a report
Hardware reports can contain serial numbers, IP addresses and other values that are useful to an attacker or simply unnecessary for support. Add -sanitize before redirecting output outside the machine:
$ sudo lshw -json -sanitize -notime > hardware-sanitised.json
$ test -s hardware-sanitised.json && echo 'sanitised report written'
sanitised report written
Sanitisation is a reduction step, not a guarantee that the file contains no identifying information. Hardware models, bus addresses and network interface names may still identify a host in context. Inspect the file before uploading it, and remove the copy when you no longer need it. A report written with shell redirection is an ordinary file owned by the shell's user, so check its permissions and storage location.
Do not publish raw output from lshw in a bug report by habit. First decide what the recipient needs, use -sanitize, and review the result. This is especially relevant for the HTML and XML formats, which may contain the same underlying identifying values as text or JSON.
6. Save a database only when you need one
The -dump option writes collected information to the filename you provide as an SQLite database while also displaying the report. Choose a new path deliberately:
$ sudo lshw -dump /tmp/hardware.sqlite
$ file /tmp/hardware.sqlite
/tmp/hardware.sqlite: SQLite 3.x database
This is a state-changing example because it creates a file, and the dump can contain sensitive information. Use a private directory or an explicit permissions policy when the report must persist. Do not overwrite an existing evidence file until you have checked its path. When the database is no longer needed, remove that specific file with rm -- /tmp/hardware.sqlite; deletion is irreversible unless another copy exists.
If you only need a portable report, prefer redirected JSON, XML or text and skip the database. A failed collection can still leave a partial output file, so check its size and contents before treating it as a complete inventory.
7. Investigate incomplete results safely
Use -quiet only when status messages would interfere with a consumer. It does not grant access or make detection more accurate. The -enable and -disable options turn individual detection tests on or off for that invocation, including tests such as dmi, pci, usb, scsi and network:
$ sudo lshw -disable dmi -short
$ sudo lshw -enable pci -short
These options change how lshw probes the current scan; they do not enable hardware, load a driver or alter kernel configuration. Use them to isolate a detection problem, then compare with an ordinary root scan. If a device remains absent, check the kernel and platform tools named by the manual, such as lspci or lsusb, rather than inventing a missing lshw class.
Done means
- You confirmed the installed lshw binary and package version.
- You ran a root scan when complete detail mattered and recognised partial-scan warnings.
- You used
-short, a class filter or-businfoto keep the result focused. - You selected JSON or XML for automation and used
-notimewhen volatile timestamps were noise. - You used
-sanitizeand reviewed a report before sharing it. - Any saved dump file has a deliberate path, permissions and a clear removal plan.