What is Linux Sar command and how to use it.

 The sar (System Activity Reporter) command is a powerful utility in Linux/Unix systems used to collect, report, and analyze system activity. It is part of the sysstat package and provides detailed insights into various system resources, such as CPU, memory, disk I/O, network, and more. The sar command is particularly useful for performance monitoring and troubleshooting.


Key Features of sar

  1. Historical Data Collection:

    • sar collects system activity data at regular intervals and stores it in log files (usually located in /var/log/sa/ or /var/log/sysstat/).

    • This allows you to analyze past performance and identify trends.

  2. Real-Time Monitoring:

    • You can use sar to monitor system activity in real-time.

  3. Comprehensive Reporting:

    • sar provides detailed reports on various system metrics, including:

      • CPU usage

      • Memory usage

      • Disk I/O

      • Network activity

      • Process and task creation

      • Swap usage

      • Paging activity


How to Use sar

1. Install sysstat Package

  • On most Linux distributions, sar is part of the sysstat package. Install it if not already installed:

    bash
    Copy
    sudo apt-get install sysstat  # For Debian/Ubuntu
    sudo yum install sysstat      # For CentOS/RHEL
  • Enable and start the sysstat service to collect data:

    bash
    Copy
    sudo systemctl enable sysstat
    sudo systemctl start sysstat

2. View Real-Time System Activity

  • Use sar with an interval (in seconds) and count (number of reports):

    bash
    Copy
    sar <interval> <count>
  • Example: Monitor CPU usage every 2 seconds for 5 iterations:

    bash
    Copy
    sar 2 5

3. View Historical Data

  • By default, sar stores historical data in binary files (e.g., saXX files in /var/log/sa/).

  • Use sar with the -f option to specify a file:

    bash
    Copy
    sar -f /var/log/sa/saXX
  • Example: View CPU usage from a specific day's log file:

    bash
    Copy
    sar -f /var/log/sa/sa10

4. Common sar Options

  • CPU Usage:

    bash
    Copy
    sar -u
    • Reports CPU utilization (user, system, idle, etc.).

  • Memory Usage:

    bash
    Copy
    sar -r
    • Reports memory and swap usage.

  • Disk I/O:

    bash
    Copy
    sar -d
    • Reports disk activity (read/write operations, throughput).

  • Network Activity:

    bash
    Copy
    sar -n DEV
    • Reports network interface statistics (packets, errors, throughput).

  • Paging and Swapping:

    bash
    Copy
    sar -B
    • Reports paging and swapping activity.

  • Process and Task Creation:

    bash
    Copy
    sar -c
    • Reports process and task creation rates.

  • Load Average:

    bash
    Copy
    sar -q
    • Reports system load average and run queue statistics.


5. Generate a Report for a Specific Time Range

  • Use the -s (start time) and -e (end time) options to filter data:

    bash
    Copy
    sar -s 10:00:00 -e 12:00:00

6. Save Output to a File

  • Redirect sar output to a file for later analysis:

    bash
    Copy
    sar -u 1 10 > cpu_usage.txt

Example Outputs

CPU Usage (sar -u)

Copy
Linux 5.4.0-42-generic (hostname) 	10/10/2023 	_x86_64_	(4 CPU)

10:00:01 AM     CPU     %user     %nice   %system   %iowait    %steal     %idle
10:10:01 AM     all      5.23      0.00      1.45      0.12      0.00     93.20
10:20:01 AM     all      4.89      0.00      1.32      0.10      0.00     93.69

Memory Usage (sar -r)

Copy
Linux 5.4.0-42-generic (hostname) 	10/10/2023 	_x86_64_	(4 CPU)

10:00:01 AM kbmemfree kbmemused  %memused kbbuffers  kbcached  kbcommit   %commit
10:10:01 AM   1024000   2048000     66.67    102400    512000   3072000     50.00
10:20:01 AM   1024000   2048000     66.67    102400    512000   3072000     50.00

Disk I/O (sar -d)

Copy
Linux 5.4.0-42-generic (hostname) 	10/10/2023 	_x86_64_	(4 CPU)

10:00:01 AM       DEV       tps  rd_sec/s  wr_sec/s  avgrq-sz  avgqu-sz     await     svctm     %util
10:10:01 AM       sda      1.23      4.56      8.90     10.89      0.12      5.67      1.23      0.15
10:20:01 AM       sda      1.45      5.67      9.87     10.78      0.15      6.78      1.45      0.20

Key Metrics to Monitor

  1. CPU:

    • High %user or %system indicates CPU-bound processes.

    • High %iowait indicates I/O bottlenecks.

  2. Memory:

    • Low kbmemfree and high %memused indicate memory pressure.

    • High kbcommit indicates overcommitment of memory.

  3. Disk I/O:

    • High %util indicates disk saturation.

    • High await indicates slow I/O response times.

  4. Network:

    • High rxkB/s or txkB/s indicates network traffic.

    • Errors or drops indicate network issues.


Conclusion

The sar command is an invaluable tool for system administrators and performance analysts. It provides a comprehensive view of system activity, helping you identify bottlenecks, troubleshoot performance issues, and optimize system resources. By leveraging historical data and real-time monitoring, you can ensure your system runs efficiently and reliably.

New 

Comments

Popular posts from this blog

HANA certification questions

Troubleshoot Oracle performance issue