Inspect USB Devices Safely with lsusb

lsusb shows every USB device Linux can enumerate, along with its bus and vendor IDs. It is the first read-only check for a device that will not mount, a keyboard that stopped responding, or a webcam Windows saw but Linux did not. Allow about ten minutes, plus time to unplug and reconnect a device if you need to pin one down.

1. Check the installed command

This guide follows usbutils 017, the version installed on the reference machine. The package is usbutils 1:017-3build1, and the command reports lsusb (usbutils) 017. Other releases can format descriptive names or verbose fields differently, so treat the option meanings as stable but the exact output as host-specific.

$ command -v lsusb
/usr/bin/lsusb
$ lsusb --version
lsusb (usbutils) 017

Checkpoint: if command -v prints nothing, install the usbutils package through your normal distribution method. Do not copy a binary from an unrelated host just to make the command available.

2. List the devices Linux can see

Run the default command first. It scans the USB buses and prints one line per enumerated device. The bus and device numbers are decimal; the vendor and product identifiers after ID are hexadecimal.

$ lsusb
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
Bus 002 Device 001: ID 1d6b:0003 Linux Foundation 3.0 root hub

Your list will be different. A physical device can carry a generic name, especially when its descriptive strings or the local hardware database do not supply more detail. Either way, the line gives you identifiers worth recording before you dig further.

Do not treat an absent device as proof its driver is missing. Check its cable, power, hub and connection first, then rerun lsusb: enumeration happens before many higher-level drivers expose a usable interface.

3. Filter one bus or device number

Use -s when you already know the decimal bus and device numbers. You can give a bus, a device number, or both. This is a display filter, not a request to reset or detach anything.

$ lsusb -s 001:001
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
$ lsusb -s 001
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub

Device numbers can change after reconnecting hardware or restarting a bus. If an old filter returns no line, list the buses again rather than assuming the device has failed. The command returns a non-zero status when a specifically requested device is not found, which is what makes a targeted check useful in a script.

4. Filter by vendor and product ID

Use -d with a hexadecimal vendor and product ID when the device number is transient but the hardware identity is known. The two parts are separated by a colon.

$ lsusb -d 1d6b:0002
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub

You can omit either ID for a broader match, but keeping both makes the result easier to review. Do not swap the numeric bases: -s 001:001 uses decimal bus and device numbers, while -d 1d6b:0002 uses hexadecimal vendor and product IDs.

Checkpoint: record the complete ID value and the bus line before changing cables, so you have a comparison point after reconnecting the hardware.

5. Show the physical USB tree

Use -t to see hubs, ports, negotiated speeds and how devices relate to each other. This often explains why a device sits behind a hub, or why a USB 3 device is running at a lower speed than expected.

$ lsusb -t
/:  Bus 001.Port 001: Dev 001, Class=root_hub, Driver=xhci_hcd/12p, 480M
/:  Bus 002.Port 001: Dev 001, Class=root_hub, Driver=xhci_hcd/6p, 5000M

The speed is shown in megabits per second. 480M is USB high-speed; 5000M is a faster SuperSpeed link. The tree describes what was negotiated on this host, not the maximum printed on the device's packaging.

6. Read detailed descriptors when needed

Use -v for verbose information, including configuration descriptors for the current speed and available class descriptors. Start with a filter if you are investigating one device, because unfiltered output can run long.

$ lsusb -d 1d6b:0002 -v
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
Device Descriptor:
  ...

The exact fields and indentation vary with the device and usbutils release. The ellipsis above is shorthand for omitted output in this guide, not something to paste into a command. Use the full result when comparing descriptors, and avoid publishing serial numbers or other identifying fields in a support ticket unless they are actually needed.

Verbose scanning is still just an observation. It does not reload a driver, reset a port or change device configuration. If permission errors appear for a particular device, retry only when your local policy allows it, and use the smallest necessary privilege.

7. Use a device path only for a specific root-owned inspection

The -D option skips the normal bus scan and reads one device file directly, such as /dev/bus/usb/001/001. The manual documents this as a detailed inspection equivalent to -v, and it requires root. This is the only example in this guide that needs elevation.

$ sudo lsusb -D /dev/bus/usb/001/001
Bus 001 Device 001: ID 1d6b:0002 Linux Foundation 2.0 root hub
Device Descriptor:
  ...

Check the path first with an ordinary listing:

$ ls -l /dev/bus/usb/001/001
crw-rw-r-- 1 root root 189, 0 ... /dev/bus/usb/001/001

Bus device files are not stable names. Do not save one as a permanent identifier, and do not reach for sudo as a first response to a missing device. If the path has disappeared, list the buses again. No undo is required, because these commands only read descriptors.

8. Recover from an unhelpful result

If lsusb shows only root hubs, check the physical connection and repeat the default listing. Try a different port without changing any driver configuration. If a device appears and disappears, compare lsusb -t output over time and inspect the system log with your distribution's normal log-reading tool.

If a filter prints nothing, confirm the numeric base and whether the bus or device number has changed. If names are less descriptive than expected, keep the hexadecimal ID: it is the reliable part of the line for further filtering. If lsusb -v produces too much output, fall back to -s or -d before asking for elevated access.

Done means