Resource Monitoring

Watching System Resources

Beyond logs telling you what happened, you often need to know what a system is doing right now - is it CPU-bound, memory-starved, or waiting on slow disk I/O? Each of these tools answers a slightly different flavor of that question.

CommandWatches
top / htopCPU, memory, per-process
free -hMemory & swap
vmstat 1CPU/memory/IO over time
iostatDisk I/O (sysstat)
sarHistorical stats (sysstat)
uptimeLoad average
watch -n2 cmdRe-run a command every 2s

watch is a small but genuinely useful trick worth calling out on its own: instead of manually re-running a command over and over to watch a value change, watch -n2 cmd re-runs it automatically every 2 seconds and refreshes the screen in place - handy for watching free -h or df -h tick over live during a load test or cleanup.

$ free -h
              total   used   free  shared  buff/cache  available
Mem:           7.7Gi  2.1Gi  3.4Gi   210Mi       2.2Gi      5.1Gi

This is one of the most misread command outputs in all of Linux, so it's worth walking through carefully: the kernel deliberately uses spare RAM for filesystem buffers and caches (buff/cache, here 2.2 GiB) to speed up future disk reads - it's not "used" in any way that matters, because the kernel will instantly evict it the moment a real application actually needs that memory. Looking only at the free column (3.4 GiB) makes the system look far more memory-constrained than it actually is.

Warning: The available column, not free, is the number that answers "how much memory could a new process actually get right now?" - it already accounts for cache the kernel would happily give up on demand. Beginners regularly panic seeing a small free value on an otherwise healthy, fast machine; experienced admins glance straight at available and move on. Watch available trending steadily toward zero over time - that's the real early warning sign of memory pressure, not a merely small free number.