Resource Monitoring
Watching System Resources
Beyond logs telling you what happened, you often need to know what a system is doing right now - is it CPU-bound, memory-starved, or waiting on slow disk I/O? Each of these tools answers a slightly different flavor of that question.
| Command | Watches |
|---|---|
top / htop | CPU, memory, per-process |
free -h | Memory & swap |
vmstat 1 | CPU/memory/IO over time |
iostat | Disk I/O (sysstat) |
sar | Historical stats (sysstat) |
uptime | Load average |
watch -n2 cmd | Re-run a command every 2s |
watch is a small but genuinely useful trick worth calling out on its own: instead of manually re-running a command over and over to watch a value change, watch -n2 cmd re-runs it automatically every 2 seconds and refreshes the screen in place - handy for watching free -h or df -h tick over live during a load test or cleanup.
$ free -h
total used free shared buff/cache available
Mem: 7.7Gi 2.1Gi 3.4Gi 210Mi 2.2Gi 5.1Gi
This is one of the most misread command outputs in all of Linux, so it's worth walking through carefully: the kernel deliberately uses spare RAM for filesystem buffers and caches (buff/cache, here 2.2 GiB) to speed up future disk reads - it's not "used" in any way that matters, because the kernel will instantly evict it the moment a real application actually needs that memory. Looking only at the free column (3.4 GiB) makes the system look far more memory-constrained than it actually is.
Warning: Theavailablecolumn, notfree, is the number that answers "how much memory could a new process actually get right now?" - it already accounts for cache the kernel would happily give up on demand. Beginners regularly panic seeing a smallfreevalue on an otherwise healthy, fast machine; experienced admins glance straight atavailableand move on. Watchavailabletrending steadily toward zero over time - that's the real early warning sign of memory pressure, not a merely smallfreenumber.