How to see what is using CPU, memory and disk on your VPS

Five commands that ship with the system tell you the essentials: uptime (load), top (who uses processor and memory), free -h (memory), df -h (disk) and ss -tulpn (what listens on the network). To follow things over time, not only when you happen to look, there are simple tools. On an unmanaged VPS, watching this is part of the job for whoever owns it.

The commands, by question

The question The command What to read
Is the server heavy? uptime The last three numbers are the load average (1, 5 and 15 minutes). Compare with the number of processors nproc shows: a load steadily above it means processes waiting.
Who uses processor and memory? top (or htop, easier to read, installed with the package manager) Press M to sort by memory and P by processor; q to quit.
How much memory is left? free -h The “available” column. A low “free” is normal, because Linux fills free memory with cache.
Is the disk filling up? df -h and df -i The percentage used and the inodes. To find what takes it: finding what fills the disk.
Is the disk slow? vmstat 1 5 The “wa” column: time waiting for the disk. High and steady means a slow or overloaded disk.
Which ports are open? sudo ss -tulpn Each line is a program listening. Something you do not recognise deserves a question.
Which processes are the biggest? ps aux --sort=-%cpu | head or --sort=-%mem The top ten by processor or by memory.

Reading the top of top

The processor line shows percentages: us (your programs), sy (the system), wa (waiting on disk) and st (steal). st is time the physical machine hosting your VPS did not give you. If it is high and steady, your VPS is losing processor for reasons that are not inside your server; note the times and open a ticket, so we can look from our side.

Following it over time

1 The sysstat package. Install it (sudo apt install sysstat on Debian and Ubuntu) and switch on collection following the distribution’s documentation. Then sar shows processor, memory and disk for earlier hours and days: the answer to “what happened at three in the morning?”.
2 An alert from outside. An external monitoring service that visits your site every few minutes e-mails you when it does not answer, even if the server is too sick to complain.
3 A dashboard of your own, if you want one. There are third-party open-source programs (for example Netdata, or Prometheus with node_exporter) that draw graphs of the server. They are yours: you install, update and protect them, and our support does not install or repair them (how far our support goes).
A monitoring dashboard is one more program to defend. If you install one, do not leave it open to the internet without a password and HTTPS, and close its port in the firewall if only you use it (ports and firewall).
Keep the before and the after. When you change a configuration to improve performance, note the numbers first (free -h, the load, the site’s response time), so you know whether the change helped. For the site side, see the site is slow: what to measure before you change plan.

Do the numbers show a problem that looks like the machine or the network? Send us the times and what you saw, and we will check on our side.

Open a support ticket

SEE ALSO

Out of memory: the OOM killer

No space left on device: what fills the disk

The site is slow: what to measure before you change plan

Keeping your VPS secure

RECOMMENDED PRODUCT

VPS server with root access

Resources of your own, the OS you choose, reinstall whenever you like. from ₦12.600,00/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?