Quick Linux Process Troubleshooting

When a Linux system feels slow, start by tying the symptom back to a process: CPU, memory, disk I/O, or the network.

Four questions, four commands ↓

First pass

Four common questions

When troubleshooting a Linux system, four common questions are:

  • Which process is using CPU?
  • Which process is using memory?
  • Which process is doing disk I/O?
  • Which process is using the network?

These four commands give you a quick first-level view.

CPU

Which process is using CPU?

ps aux --sort=-%cpu

This shows all running processes and sorts them by CPU usage, highest first. It is useful when the system feels slow and you want to quickly identify CPU-intensive processes.

High CPU? ps aux --sort=-%cpu Identify the top CPU-consuming process
Memory

Which process is using memory?

ps aux --sort=-%mem

This shows all running processes and sorts them by memory usage, highest first. It helps identify which applications are consuming the most RAM.

High memory usage? ps aux --sort=-%mem Identify the top memory-consuming process
Disk I/O

Which process is doing disk I/O?

pidstat -d 1 2

This shows per-process disk I/O activity.

Here:

-d → Show disk I/O statistics
1  → Collect every 1 second
2  → Produce 2 reports

It helps answer: which process is reading from or writing to disk?

Typical fields include read and write throughput for each process.

High disk I/O? pidstat -d 1 2 Identify which process is reading or writing heavily
Network

Which process is using the network?

ss -tunap

This shows TCP and UDP sockets, along with connection details and the process using them when permissions allow.

The options mean:

-t → TCP
-u → UDP
-n → Show numeric IP addresses and ports
-a → Show all sockets
-p → Show associated process

It helps answer questions such as:

  • Which ports are listening?
  • Which processes own those ports?
  • Which remote systems are connected?
  • Are connections established or waiting?
Network activity? ss -tunap Socket / Port / Connection / Process
Simple troubleshooting view

Keep the four commands together

CPU ps aux --sort=-%cpu Memory ps aux --sort=-%mem Disk I/O pidstat -d 1 2 Network ss -tunap
These commands are useful as a first-pass troubleshooting toolkit because they let you quickly connect resource usage back to a specific process.