What is Linux Sar command and how to use it.
The sar (System Activity Reporter) command is a powerful utility in Linux/Unix systems used to collect, report, and analyze system activity. It is part of the sysstat package and provides detailed insights into various system resources, such as CPU, memory, disk I/O, network, and more. The sar command is particularly useful for performance monitoring and troubleshooting.
Key Features of sar
Historical Data Collection:
sarcollects system activity data at regular intervals and stores it in log files (usually located in/var/log/sa/or/var/log/sysstat/).This allows you to analyze past performance and identify trends.
Real-Time Monitoring:
You can use
sarto monitor system activity in real-time.
Comprehensive Reporting:
sarprovides detailed reports on various system metrics, including:CPU usage
Memory usage
Disk I/O
Network activity
Process and task creation
Swap usage
Paging activity
How to Use sar
1. Install sysstat Package
On most Linux distributions,
saris part of thesysstatpackage. Install it if not already installed:sudo apt-get install sysstat # For Debian/Ubuntu sudo yum install sysstat # For CentOS/RHEL
Enable and start the
sysstatservice to collect data:sudo systemctl enable sysstat sudo systemctl start sysstat
2. View Real-Time System Activity
Use
sarwith an interval (in seconds) and count (number of reports):sar <interval> <count>
Example: Monitor CPU usage every 2 seconds for 5 iterations:
sar 2 5
3. View Historical Data
By default,
sarstores historical data in binary files (e.g.,saXXfiles in/var/log/sa/).Use
sarwith the-foption to specify a file:sar -f /var/log/sa/saXXExample: View CPU usage from a specific day's log file:
sar -f /var/log/sa/sa10
4. Common sar Options
CPU Usage:
sar -uReports CPU utilization (user, system, idle, etc.).
Memory Usage:
sar -rReports memory and swap usage.
Disk I/O:
sar -dReports disk activity (read/write operations, throughput).
Network Activity:
sar -n DEVReports network interface statistics (packets, errors, throughput).
Paging and Swapping:
sar -BReports paging and swapping activity.
Process and Task Creation:
sar -cReports process and task creation rates.
Load Average:
sar -qReports system load average and run queue statistics.
5. Generate a Report for a Specific Time Range
Use the
-s(start time) and-e(end time) options to filter data:sar -s 10:00:00 -e 12:00:00
6. Save Output to a File
Redirect
saroutput to a file for later analysis:sar -u 1 10 > cpu_usage.txt
Example Outputs
CPU Usage (sar -u)
Linux 5.4.0-42-generic (hostname) 10/10/2023 _x86_64_ (4 CPU) 10:00:01 AM CPU %user %nice %system %iowait %steal %idle 10:10:01 AM all 5.23 0.00 1.45 0.12 0.00 93.20 10:20:01 AM all 4.89 0.00 1.32 0.10 0.00 93.69
Memory Usage (sar -r)
Linux 5.4.0-42-generic (hostname) 10/10/2023 _x86_64_ (4 CPU) 10:00:01 AM kbmemfree kbmemused %memused kbbuffers kbcached kbcommit %commit 10:10:01 AM 1024000 2048000 66.67 102400 512000 3072000 50.00 10:20:01 AM 1024000 2048000 66.67 102400 512000 3072000 50.00
Disk I/O (sar -d)
Linux 5.4.0-42-generic (hostname) 10/10/2023 _x86_64_ (4 CPU) 10:00:01 AM DEV tps rd_sec/s wr_sec/s avgrq-sz avgqu-sz await svctm %util 10:10:01 AM sda 1.23 4.56 8.90 10.89 0.12 5.67 1.23 0.15 10:20:01 AM sda 1.45 5.67 9.87 10.78 0.15 6.78 1.45 0.20
Key Metrics to Monitor
CPU:
High
%useror%systemindicates CPU-bound processes.High
%iowaitindicates I/O bottlenecks.
Memory:
Low
kbmemfreeand high%memusedindicate memory pressure.High
kbcommitindicates overcommitment of memory.
Disk I/O:
High
%utilindicates disk saturation.High
awaitindicates slow I/O response times.
Network:
High
rxkB/sortxkB/sindicates network traffic.Errors or drops indicate network issues.
Conclusion
The sar command is an invaluable tool for system administrators and performance analysts. It provides a comprehensive view of system activity, helping you identify bottlenecks, troubleshoot performance issues, and optimize system resources. By leveraging historical data and real-time monitoring, you can ensure your system runs efficiently and reliably.
Comments
Post a Comment