Inspecting Processes
Viewing Processes
A process is a running instance of a program - the program's code loaded into memory, plus its own private state (variables, open files, current CPU registers). Run the same program twice and you get two separate processes, each with its own identity and its own numeric PID (Process ID).
Analogy: A program on disk is like a recipe in a cookbook - static instructions. A process is what happens when someone actually starts cooking from that recipe: ingredients in progress, a pot on the stove, a specific point reached in the steps. Two cooks can follow the same recipe (the same program) at the same time as two completely independent processes, each at a different step, neither affecting the other's pot.
| Command | Purpose |
|---|---|
ps aux | Snapshot of all processes (BSD style) |
ps -ef | Snapshot (System V style) |
top / htop | Live, interactive view |
pgrep -a nginx | Find PIDs by name |
pstree | Process hierarchy |
uptime | Load averages |
ps gives you a one-time snapshot the instant you run it - the process list has already moved on by the time you finish reading it. top/htop instead refresh continuously, which is what you want when you're actively watching something like CPU usage climb in real time.
$ ps -ef | head -2
UID PID PPID C STIME TTY TIME CMD
root 1 0 0 09:00 ? 00:00:02 /sbin/init
Reading this: PID is the process's own ID, PPID is its parent's PID (the process that started it), C is recent CPU usage, STIME is when it started, and TIME is total CPU time consumed (not wall-clock time - a process idling for hours can still show 00:00:00).
Load average (from uptime) reports how much demand there's been on the CPU over the last 1, 5, and 15 minutes - specifically, the average number of processes wanting to run but waiting their turn. A load average roughly equal to your CPU count means the machine is fully but not overwhelmed; well above it means processes are queuing and waiting.
Tip: Every process has exactly one parent - PID 1 is the very first process started by the kernel (initorsystemd), and it has no parent at all. If a process's parent exits before it does, the kernel re-parents the orphan to PID 1 so nothing is ever truly parentless - you can see this inpstreewhen a long-running background process appears to hang directly offinitinstead of the shell that originally launched it.