Andrew Mercer
on this page

What it is

sysstat is a bundle of performance tools plus a collector that records system activity every few minutes, so you can look at last Tuesday's CPU or disk figures.

sudo dnf -y install sysstat        # or apt-get install sysstat
sudo systemctl enable --now sysstat

On Debian and Ubuntu, set ENABLED="true" in /etc/default/sysstat. Data files land in /var/log/sa/ (RHEL) or /var/log/sysstat/ (Debian), named saDD for the day of the month.

Tool Purpose
sar collect and report all system activity statistics
sadc the data collector (sar backend)
sa1 / sa2 cron/systemd helpers: store binary samples / build daily summaries
sadf export sar data as CSV, JSON, XML, and more, for other tools
iostat CPU and per-device I/O statistics (see iostat)
mpstat per-CPU statistics
pidstat per-process statistics
nfsiostat, cifsiostat NFS and CIFS client statistics

sar: live and historical

Live: sar <options> <interval> <count>. Historical: sar <options> -f /var/log/sa/saDD.

# CPU
sar -u 1 10                     # overall CPU
sar -P ALL 1 10                 # each core
sar -P ALL -f /var/log/sa/sa04  # each core, on the 4th of the month

# Memory and swap
sar -r 1 10                     # memory
sar -S 1 10                     # swap
sar -B 1 10                     # paging
sar -W 1 10                     # swap in/out pages
sar -H 1 10                     # huge pages

# Disk
sar -b 1 10                     # overall I/O and transfer rates
sar -d -p 1 10                  # per device, with device names

# Processes and load
sar -w 1 10                     # processes created, context switches
sar -q 1 10                     # run queue and load averages

# Network
sar -n DEV 1 10                 # per-interface throughput
sar -n EDEV 1 1                 # per-interface errors
sar -n TCP,ETCP 1 10            # TCP segments and errors/retransmits
sar -n SOCK 1 10                # sockets in use

# A specific window in history
sar -q -f /var/log/sa/sa04 -s 10:00:00 -e 11:00:00

Export

sadf -d /var/log/sa/sa04 -- -u > cpu.csv        # semicolon-separated
sadf -j /var/log/sa/sa04 -- -r > mem.json

Per-process and per-CPU

mpstat -P ALL 1 5
pidstat 1 5                     # CPU per process
pidstat -d 1 5                  # disk I/O per process
pidstat -r 1 5                  # memory per process

Related: vmstat, atop, pcp.