Quick Linux Process Troubleshooting
When a Linux system feels slow, start by tying the symptom back to a process: CPU, memory, disk I/O, or the network.
Four questions, four commands ↓
Four common questions
When troubleshooting a Linux system, four common questions are:
- Which process is using CPU?
- Which process is using memory?
- Which process is doing disk I/O?
- Which process is using the network?
These four commands give you a quick first-level view.
Which process is using CPU?
ps aux --sort=-%cpu
This shows all running processes and sorts them by CPU usage, highest first. It is useful when the system feels slow and you want to quickly identify CPU-intensive processes.
ps aux --sort=-%cpu
Identify the top CPU-consuming process
Which process is using memory?
ps aux --sort=-%mem
This shows all running processes and sorts them by memory usage, highest first. It helps identify which applications are consuming the most RAM.
ps aux --sort=-%mem
Identify the top memory-consuming process
Which process is doing disk I/O?
pidstat -d 1 2
This shows per-process disk I/O activity.
Here:
-d → Show disk I/O statistics
1 → Collect every 1 second
2 → Produce 2 reports
It helps answer: which process is reading from or writing to disk?
Typical fields include read and write throughput for each process.
pidstat -d 1 2
Identify which process is reading or writing heavily
Which process is using the network?
ss -tunap
This shows TCP and UDP sockets, along with connection details and the process using them when permissions allow.
The options mean:
-t → TCP
-u → UDP
-n → Show numeric IP addresses and ports
-a → Show all sockets
-p → Show associated process
It helps answer questions such as:
- Which ports are listening?
- Which processes own those ports?
- Which remote systems are connected?
- Are connections established or waiting?
ss -tunap
Socket / Port / Connection / Process
Keep the four commands together
ps aux --sort=-%cpu
Memory
ps aux --sort=-%mem
Disk I/O
pidstat -d 1 2
Network
ss -tunap
These commands are useful as a first-pass troubleshooting toolkit because they let you quickly connect resource usage back to a specific process.