Andrew Mercer
on this page

Basic usage

top
top - 21:20:01 up 8 days, 18:26,  4 users,  load average: 1.62, 1.62, 1.59
Tasks: 250 total,   2 running, 247 sleeping,   0 stopped,   1 zombie
%Cpu(s):  2.2 us,  0.8 sy,  0.0 ni, 96.6 id,  0.3 wa,  0.0 hi,  0.1 si,  0.0 st
MiB Mem :  12001.2 total,    235.7 free,  11766.1 used,    419.8 buff/cache
MiB Swap:  14048.0 total,  13970.0 free,     78.0 used.   8300.0 avail Mem

  PID USER      PR  NI    VIRT    RES    SHR S  %CPU  %MEM     TIME+ COMMAND
 9969 qemu      20   0  574m    282m  9744 S  99.0   2.4 202:26.55 qemu-kvm

Field formats differ slightly between top versions. Batch mode for scripts: top -b -n 1 | head -20.

Load average

The three load numbers are for the last 1, 5, and 15 minutes. One fully busy CPU core equals 1.00, so a 4-core machine is saturated near 4.00. See uptime.

Header: CPU states

Field Meaning What to watch
us user-space code high means applications are busy
sy kernel code (system calls, scheduling, interrupts) persistently high suggests heavy I/O, many syscalls, or interrupt storms
ni user code running at adjusted (nice) priority
id idle
wa waiting for I/O sustained values above roughly 20–30% point to a storage or network bottleneck
hi / si hardware / software interrupts rarely above a few percent
st time stolen by the hypervisor high in a VM means the host is oversubscribed

Header: memory

Free memory on a long-running Linux box is usually small because the kernel uses spare RAM for caches. avail Mem (or the available column in free -h) is the number that matters: it estimates how much can be allocated without swapping. Actual pressure shows as swap in/out activity (vmstat 1, columns si/so) rather than a low free.

Per-process columns

Column Meaning
PID, USER process id and owner
PR, NI scheduling priority and nice value (-20 highest priority to 19 lowest)
VIRT total virtual address space the process has mapped. Not the same as memory in use
RES resident (physical) memory
SHR portion of RES that is shared with other processes
S state: R running, S sleeping, D uninterruptible (usually I/O), Z zombie, T stopped
%CPU, %MEM share of CPU time and physical memory
TIME+ total CPU time consumed

Processes stuck in state D are what push load up while the CPU sits idle. To cross-check a PID: ps -o pid,etime,time,cmd -p <pid>.

Interactive keys

Key Action
h or ? help
1 toggle per-CPU display
M / P / T sort by memory / CPU / time
H toggle threads
u filter by user
c toggle full command line
d or s change refresh interval
k kill a process (prompts for PID and signal)
r renice a process
f choose columns and sort field (add P, "last used CPU", to see CPU migration)
W save the current configuration to ~/.config/procps/toprc
q quit

Processes bouncing between CPUs lose cache contents, so a large number of CPU migrations on a busy multi-core box is worth investigating. Add the "last used CPU" column via f to see it.

Simulate a load of 1.00

while true; do :; done       # one core at 100%; Ctrl+C to stop

Run one per core to saturate the machine (for example while testing alerting or turbostat).

Better alternatives

htop (colour, tree view, mouse), btop, and atop (records history) are worth installing on servers you look after.