Linux sar Command
1. What is the sar command?
sar (System Activity Reporter) is a powerful performance monitoring tool on Linux systems and is part of the sysstat package. It can collect, report, and save various activity information about the system, including:
- CPU usage
- Memory utilization
- I/O activity
- Network statistics
- Process activity
- Device load, etc.
1.1 Advantages of the sar command
- Historical data analysis: Allows you to view the system status at any point in the past
- Comprehensive monitoring: Covers all key performance metrics of the system
- Low overhead: Data collection has minimal impact on system performance
- Automation: Can be configured to automatically collect data periodically
2. Installation and Basic Configuration
2.1 Installing the sysstat Package
On most Linux distributions, the sar command can be obtained by installing the sysstat package:
# Ubuntu/Debian sudo apt-get install sysstat # CentOS/RHEL sudo yum install sysstat # Fedora sudo dnf install sysstat
2.2 Enabling Data Collection
After installation, the data collection service needs to be enabled:
Example
# Edit the configuration file
sudo vi /etc/default/sysstat
# Change ENABLED="false" to
ENABLED="true"
# Restart the service
sudo systemctl restart sysstat
sudo vi /etc/default/sysstat
# Change ENABLED="false" to
ENABLED="true"
# Restart the service
sudo systemctl restart sysstat
By default, sar collects data every 10 minutes and saves it in/var/log/sysstat/the directory.
3. Basic Syntax and Common Parameters
3.1 Basic Syntax Format
sar [选项] [间隔时间] [次数]
3.2 Explanation of Common Parameters
| Parameter | Description |
|---|---|
| -A | Display all reports |
| -u | Display CPU utilization |
| -r | Display memory usage |
| -b | Display I/O and transfer rate statistics |
| -n DEV | Display network device statistics |
| -q | Display system load and queue length |
| -d | Display disk activity |
| -P ALL | Display statistics for each CPU |
| -s | Specify start time |
| -e | Specify end time |
| -f | Read data from the specified file |
4. Practical Application Examples
4.1 Real-time Monitoring of CPU Usage
Example
# Refresh every 2 seconds, display 5 times in total
sar -u 2 5
sar -u 2 5
Example output:
Linux 5.4.0-91-generic (hostname) 03/15/2023 _x86_64_ (4 CPU) 10:30:01 AM CPU %user %nice %system %iowait %steal %idle 10:30:03 AM all 5.12 0.00 1.02 0.51 0.00 93.35 10:30:05 AM all 6.23 0.00 1.34 0.23 0.00 92.20
4.2 View Historical Memory Usage
Example
# View today's memory usage
sar -r
# View data for a specified date (file must be specified)
sar -r -f /var/log/sysstat/sa15 # Data for the 15th
sar -r
# View data for a specified date (file must be specified)
sar -r -f /var/log/sysstat/sa15 # Data for the 15th
4.3 Monitor Disk I/O Activity
Example
# Monitor disk activity, refresh every 1 second, 10 times total
sar -d 1 10
sar -d 1 10
4.4 View Network Interface Statistics
Example
# Monitor network interface activity
sar -n DEV 1 5
sar -n DEV 1 5
5. Advanced Usage and Tips
5.1 Combining Multiple Metrics for Monitoring
Example
# Monitor CPU, memory, and disk simultaneously
sar -urdb 1 5
sar -urdb 1 5
5.2 Generate Reports for a Specific Time Period
Example
# View CPU usage from 9 a.m. to 10 a.m.
sar -u -s 09:00:00 -e 10:00:00
sar -u -s 09:00:00 -e 10:00:00
5.3 Save Output to a File
Example
# Save monitoring results to a file
sar -A 1 10 > system_report.log
sar -A 1 10 > system_report.log
5.4 Monitor a Specific CPU Core
Example
# Monitor CPU0 usage
sar -P 0 1 5
sar -P 0 1 5
6. Data Interpretation Guide
6.1 CPU Metric Interpretation
| Metric | Meaning | Healthy range |
|---|---|---|
| %user | User-space CPU usage | <70% |
| %system | Kernel-space CPU usage | <30% |
| %iowait | CPU waiting for I/O time | <5% |
| %idle | CPU idle time | >20% |
6.2 Memory Metric Interpretation
| Metric | Meaning |
|---|---|
| kbmemfree | Free physical memory (KB) |
| kbmemused | Used physical memory (KB) |
| %memused | Memory usage rate |
| kbbuffers | Memory used by buffers (KB) |
| kbcached | Memory used by cache (KB) |
6.3 Disk Metric Interpretation
| Metric | Meaning |
|---|---|
| tps | Transfers per second |
| rd_sec/s | Sectors read per second |
| wr_sec/s | Sectors written per second |
| %util | Device utilization |
7. Common Troubleshooting
7.1 Identifying CPU Bottlenecks
If%useror%systemremains consistently above 80%, it may indicate:
- Compute-intensive applications
- Excessive system calls
- Need to optimize code or add CPU resources
7.2 Determining Insufficient Memory
When the following conditions occur simultaneously, there may be insufficient memory:
%memusedConsistently above 90%kbcachedValue is very low- Swap partition (
kbswpused) usage is high
7.3 Identifying I/O Bottlenecks
%iowaitHigh and disk%utilHigh indicates:
- Disk I/O becomes a bottleneck
- May need faster storage devices
- Or optimize I/O-intensive operations
Other Extensions
Linux Command Encyclopedia