Basic usage¶
top
top - 21:20:01 up 8 days, 18:26, 4 users, load average: 1.62, 1.62, 1.59
Tasks: 250 total, 2 running, 247 sleeping, 0 stopped, 1 zombie
%Cpu(s): 2.2 us, 0.8 sy, 0.0 ni, 96.6 id, 0.3 wa, 0.0 hi, 0.1 si, 0.0 st
MiB Mem : 12001.2 total, 235.7 free, 11766.1 used, 419.8 buff/cache
MiB Swap: 14048.0 total, 13970.0 free, 78.0 used. 8300.0 avail Mem
PID USER PR NI VIRT RES SHR S %CPU %MEM TIME+ COMMAND
9969 qemu 20 0 574m 282m 9744 S 99.0 2.4 202:26.55 qemu-kvm
Field formats differ slightly between top versions. Batch mode for scripts: top -b -n 1 | head -20.
Load average¶
The three load numbers are for the last 1, 5, and 15 minutes. One fully busy CPU core equals 1.00, so a 4-core machine is saturated near 4.00. See uptime.
Header: CPU states¶
| Field | Meaning | What to watch |
|---|---|---|
us |
user-space code | high means applications are busy |
sy |
kernel code (system calls, scheduling, interrupts) | persistently high suggests heavy I/O, many syscalls, or interrupt storms |
ni |
user code running at adjusted (nice) priority | |
id |
idle | |
wa |
waiting for I/O | sustained values above roughly 20–30% point to a storage or network bottleneck |
hi / si |
hardware / software interrupts | rarely above a few percent |
st |
time stolen by the hypervisor | high in a VM means the host is oversubscribed |
Header: memory¶
Free memory on a long-running Linux box is usually small because the kernel uses spare RAM for caches. avail Mem (or the available column in free -h) is the number that matters: it estimates how much can be allocated without swapping. Actual pressure shows as swap in/out activity (vmstat 1, columns si/so) rather than a low free.
Per-process columns¶
| Column | Meaning |
|---|---|
PID, USER |
process id and owner |
PR, NI |
scheduling priority and nice value (-20 highest priority to 19 lowest) |
VIRT |
total virtual address space the process has mapped. Not the same as memory in use |
RES |
resident (physical) memory |
SHR |
portion of RES that is shared with other processes |
S |
state: R running, S sleeping, D uninterruptible (usually I/O), Z zombie, T stopped |
%CPU, %MEM |
share of CPU time and physical memory |
TIME+ |
total CPU time consumed |
Processes stuck in state D are what push load up while the CPU sits idle. To cross-check a PID: ps -o pid,etime,time,cmd -p <pid>.
Interactive keys¶
| Key | Action |
|---|---|
h or ? |
help |
1 |
toggle per-CPU display |
M / P / T |
sort by memory / CPU / time |
H |
toggle threads |
u |
filter by user |
c |
toggle full command line |
d or s |
change refresh interval |
k |
kill a process (prompts for PID and signal) |
r |
renice a process |
f |
choose columns and sort field (add P, "last used CPU", to see CPU migration) |
W |
save the current configuration to ~/.config/procps/toprc |
q |
quit |
Processes bouncing between CPUs lose cache contents, so a large number of CPU migrations on a busy multi-core box is worth investigating. Add the "last used CPU" column via f to see it.
Simulate a load of 1.00¶
while true; do :; done # one core at 100%; Ctrl+C to stop
Run one per core to saturate the machine (for example while testing alerting or turbostat).
Better alternatives¶
htop (colour, tree view, mouse), btop, and atop (records history) are worth installing on servers you look after.