What it is¶
sysstat is a bundle of performance tools plus a collector that records system activity every few minutes, so you can look at last Tuesday's CPU or disk figures.
sudo dnf -y install sysstat # or apt-get install sysstat
sudo systemctl enable --now sysstat
On Debian and Ubuntu, set ENABLED="true" in /etc/default/sysstat. Data files land in /var/log/sa/ (RHEL) or /var/log/sysstat/ (Debian), named saDD for the day of the month.
| Tool | Purpose |
|---|---|
sar |
collect and report all system activity statistics |
sadc |
the data collector (sar backend) |
sa1 / sa2 |
cron/systemd helpers: store binary samples / build daily summaries |
sadf |
export sar data as CSV, JSON, XML, and more, for other tools |
iostat |
CPU and per-device I/O statistics (see iostat) |
mpstat |
per-CPU statistics |
pidstat |
per-process statistics |
nfsiostat, cifsiostat |
NFS and CIFS client statistics |
sar: live and historical¶
Live: sar <options> <interval> <count>. Historical: sar <options> -f /var/log/sa/saDD.
# CPU
sar -u 1 10 # overall CPU
sar -P ALL 1 10 # each core
sar -P ALL -f /var/log/sa/sa04 # each core, on the 4th of the month
# Memory and swap
sar -r 1 10 # memory
sar -S 1 10 # swap
sar -B 1 10 # paging
sar -W 1 10 # swap in/out pages
sar -H 1 10 # huge pages
# Disk
sar -b 1 10 # overall I/O and transfer rates
sar -d -p 1 10 # per device, with device names
# Processes and load
sar -w 1 10 # processes created, context switches
sar -q 1 10 # run queue and load averages
# Network
sar -n DEV 1 10 # per-interface throughput
sar -n EDEV 1 1 # per-interface errors
sar -n TCP,ETCP 1 10 # TCP segments and errors/retransmits
sar -n SOCK 1 10 # sockets in use
# A specific window in history
sar -q -f /var/log/sa/sa04 -s 10:00:00 -e 11:00:00
Export¶
sadf -d /var/log/sa/sa04 -- -u > cpu.csv # semicolon-separated
sadf -j /var/log/sa/sa04 -- -r > mem.json
Per-process and per-CPU¶
mpstat -P ALL 1 5
pidstat 1 5 # CPU per process
pidstat -d 1 5 # disk I/O per process
pidstat -r 1 5 # memory per process